{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:39964e21-4b08-5c92-b61b-e92700fcdba7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-alpn-conscrypt-server",
      "version": "10.0.26-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5a910d34-e5d9-5c04-8fac-4b10727260c2",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7f6422d-7b5f-57f7-adc4-32f04c0a4990",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1b0ef97-cc41-500c-860b-7e042b4bcef6",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a82d3f2-b445-5466-9c9b-cfa9adae2bdb",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e864e43c-f295-502d-95ed-2b211d50ad38",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f4a7a8f-bbe7-569f-a9c8-4911e6f51bb5",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32301cb2-922a-51be-adca-a77e454a59e9",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:183cb6a0-e3ed-5fa0-bd48-0e15e3f781aa",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d988db3f-9894-55af-8190-2a3303824f62",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc77683-658e-5b1f-a157-6c97ae0bfd5e",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca1480c-864f-5892-944e-5316e9875caa",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e99c8fc-1ccf-58ee-b68f-8210f31a4373",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddc9965b-f631-58c8-a556-be70caaf811b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af622f55-404e-561b-97cc-5776127f4221",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64dd356-d921-5738-93d5-5124bebaa736",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd1b457-60e4-5219-91ad-5620229130ea",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ffb844-594c-566c-a682-69824b8e71bf",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b53122b-f357-5cd4-aae3-3a5b4a358d1c",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.26-tuxcare.1 of org.eclipse.jetty:jetty-alpn-conscrypt-server."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-conscrypt-server@10.0.26-tuxcare.1"
    }
  ]
}