{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:345b618c-7381-59af-95e6-07de0212767c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty.osgi",
      "name": "test-jetty-osgi",
      "version": "9.4.48.v20220622-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9acd39a2-3f10-5311-a844-515cab5f5290",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209efee0-593c-5328-8af5-d83cd9010801",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7f6e7a-184c-5bc0-8235-e70390bb449e",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b8c2174-d8c4-5fc4-984c-e04c7efb2998",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90dc26aa-8391-50ba-b998-bf03321aad2c",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26049 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:758c4e48-20ed-5e9d-9c63-f4415058f310",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb52f39a-fd7a-586f-9fb4-f76477b51247",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25ef6ceb-5188-5e81-9fbd-25ee20b4c492",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9263b8df-207c-50eb-90f6-4b55c0786971",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89fb00cb-a216-5df6-9ab4-204f8d51d11e",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03113cd-95f0-53d9-88b8-3dad141c8d96",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b5f48d-9e03-50ae-9558-5dec4e1dd1f0",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14331651-75dd-5638-b30d-c62a78084b36",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f338c7-bd13-511a-a3b5-08197a607e2e",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cae5ec88-389f-571a-85de-83c92f247d56",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a99a83-f123-57cc-b860-0db437b78033",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:507a163d-edd6-5ba8-a5ca-eea3c6511284",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03d68202-cbb8-537c-ab42-8925ea6cb07c",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d76266-6aa8-5a65-93fd-82d81c97fb36",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25dc0927-138f-57b4-ac85-6bdc24d9ca7d",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi. not_affected \u2014 CVE-2026-10051 describes an HTTP/1.1 keep-alive connection trailer cross-request leakage vulnerability in Jetty 12.x where the connection-scoped `_trailers` field is never reset between requests. The target Jetty 9.4.48.v20220622 has a different architecture (HttpChannelOverHttp + HttpChannel vs Jetty 12's HttpConnection internal structure) and already contains an upstream vendor fix from July ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a32fda-a959-5f6b-981d-7c2e968fb450",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi. Version 9.4.48.v20220622 is not vulnerable. Summary: Target repository is Jetty 9.4.48.v20220622-tuxcare.1, which is not in the affected version range. CVE-2026-1605 specifically affects Jetty 12.0.0-12.0.31 and 12.1.0-12.0.5. The architectures are fundamentally different between these major versions. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efffe4a0-9d46-5ad4-9c27-d35e335fbcdd",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab6fbd5-d7dd-5454-a3a6-a5cf9fc9ee00",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c0ce0e-9183-5d21-978f-2f68d47d98b2",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f80835c3-63dc-543f-9ee3-5fe2a4b5dfa7",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi. not_affected \u2014 Jetty 9.4.48.v20220622 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.1.8 where canonicalPath() has a semicolon-handling case that fails to update character-tracking state, breaking dot-segment detection. Version 9.4.48 uses a different architecture where canonicalPath() does not have explicit semicolon handling - semicolons are treated as regular characters in the defau..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf477c88-3627-58dd-b659-f6275b4c126b",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.48.v20220622-tuxcare.1 of org.eclipse.jetty.osgi:test-jetty-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.osgi/test-jetty-osgi@9.4.48.v20220622-tuxcare.1"
    }
  ]
}