{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f10a9430-5eeb-59cf-9948-39eb1c66c4a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.osgi",
      "name": "jetty-httpservice",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:47c312df-968d-570d-827a-5067713216ec",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b6882a-7c26-536d-9e3b-23ad75d1ac7f",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6006c179-d86f-5103-94a3-54ab2ae6c00d",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b79d703-6bc1-5d2e-a230-3fd52bec545c",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52febc93-d09b-5ad7-9f92-9da6e28372a3",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c06ca7-250e-59da-8fea-081c7ce9f911",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e848d5-f9dc-5f05-8bbc-01fd04d068be",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e13dbd6-4f5a-5fc5-9ed6-0a386c750169",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e9bdacd-870c-54e9-b5d3-a08d6eee408b",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04c05d5-ccac-5f3c-9eb7-ad338c53291c",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fd1a627-57f2-5ecb-8b2e-0661374b5ae0",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:842926ef-122d-59c1-bb7a-c13a9408f67f",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d8641b-d9b4-55d4-9525-b4c4649286bb",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99fdb87-41b0-5d31-97dc-3ed400a795b2",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb71f58d-70df-5683-910a-9a8539b58069",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7443829c-4931-52a7-a9b2-090f9e57bcd6",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803e2047-17ec-58a5-bbf5-fe4d53f2963d",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b3ae76-50e3-5397-b266-0138a3d1734b",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8822b98-bc9e-5dec-893b-687412e85810",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daa421b2-a9a1-59d0-b83b-b83568dd87db",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6cf8c9c-03f9-57ee-906d-96cbfc9570c1",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34afee35-8f70-5712-bc31-9981b8199ae2",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-httpservice."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-httpservice@10.0.26-tuxcare.3"
    }
  ]
}