{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d01ccbe1-60ff-54f4-a035-07ce0484a01d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty.osgi",
      "name": "jetty-osgi-boot-warurl",
      "version": "10.0.26-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:49cf04f3-9eb6-5c61-8f81-261a2d49812b",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffea80f-1137-5d5a-a558-1ec0ab066346",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:943805aa-4ab1-5005-8e3d-84eb1db60469",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4188c622-f570-5ffe-8625-db673e0a7606",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03915d7-b7ca-5a8e-af59-9638c1d53d90",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adc4ee20-eca3-5d49-89db-daa7592962f0",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2aec359-0e84-56c8-9992-740ecd61ef63",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33b2c4c6-7b5b-5214-9ecf-7b4443b61ecc",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57670029-89e8-5237-aabb-5b655ed5bd3e",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4ff80f0-51bb-504c-a492-4c9b1600e154",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1144d43-fca2-54dc-b41f-eb877f404e69",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0837c4d-c2b2-5b39-991e-dee77f5751bd",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0e1ef4-a650-5fb5-b128-8eb5c02635e6",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696e5aed-010e-50a4-87ab-5108d07b749b",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2737585-37e5-5492-9daf-e53c1e096a88",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d26f57-b6d4-5662-a927-053ab33ff703",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe0d7463-dba1-50eb-9779-2e071773f590",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f1ceca4-8145-537d-acae-703ea04e3b72",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a548bd26-d488-5a9f-a272-375142dac0ed",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbb0ce4d-8fb9-5ec6-a3e8-f0b97aaafe4d",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b256fa4c-c4b1-5d6f-85c3-3a3bb3de2656",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl. not_affected \u2014 Jetty 10.0.26-tuxcare.1 is NOT affected by CVE-2026-8384. The vulnerability requires Jetty 12's specific architecture where encoded path processing and dot-segment normalization occur in a single method with slash-state tracking. Jetty 10 uses a two-step architecture (decodePath then canonicalPath) without slash-state tracking, preventing the vulnerability chain from forming."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff5325e5-8088-5d39-bacd-d2b34061a671",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.3 of org.eclipse.jetty.osgi:jetty-osgi-boot-warurl."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.osgi/jetty-osgi-boot-warurl@10.0.26-tuxcare.3"
    }
  ]
}