{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5f06d44b-dcd3-54cb-b51b-bab9213c56f8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.demos",
      "name": "demos-parent",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c21b1a2e-9b23-5a51-879b-eb0d40c2d25c",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e2db742-2359-5b40-9f51-d4af6ce1b390",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5bc70b-5c4e-5bea-b012-c80fdd26bbba",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd9dcef-5c28-54f1-9301-c3b7e4cc7f36",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b2de91-eb75-5265-907e-028c4da223b5",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b38ac71-30aa-542d-9654-75a6df6b3c89",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66e8b088-f5bc-582a-8a2a-11c1de64ea09",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aceef20c-80fa-54ec-94f2-260d02b5ccbb",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c90fdd-b7a4-5956-b9ec-a5582b581fd5",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4788806c-d70f-5d34-947d-689da06137cf",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05435795-e687-5926-9c8f-f617dab9ddc1",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4be2a34-daa9-54c3-9c72-1eb005b332c8",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bce0c7-d85f-565b-a14d-5380c495469f",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01062e17-2046-5bd7-a02b-83dadcf40cd7",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18fed684-371f-5eed-9a75-1ffecf694181",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18711eae-2bbe-5212-b200-651c59d288b9",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a952d64-f6c1-513c-88e6-903fd43e8bc8",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0046d08-36ac-5080-8e6f-bfee120af948",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3aaa6f-bd94-5d60-82e1-fc3afb9ba9bb",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff294a19-d681-5985-a70f-067bcb44975c",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10dab827-b1fb-5dcc-98c3-6a6305a08d0c",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac33362-fe41-5001-99d8-4993d1b9dbc9",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.demos:demos-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.demos/demos-parent@10.0.26-tuxcare.3"
    }
  ]
}