{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:245d4c38-7974-5375-9b26-a54c7286238d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty.tests",
      "name": "test-integration",
      "version": "8.2.0.v20160908-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f4ba2bd4-5655-5de0-998e-38b0301681fc",
      "id": "CVE-2015-2080",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-2080 is a false positive for org.eclipse.jetty.tests:test-integration 8.2.0.v20160908-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8ea42dc-44bb-5858-aa92-ca141235aa92",
      "id": "CVE-2017-7656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7656 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e34c958-67a4-5c25-bd26-919791c3b3f0",
      "id": "CVE-2017-7657",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7657 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e07e806c-a20b-5a8a-af9e-32c0647f7d6d",
      "id": "CVE-2017-7658",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7658 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a3662e1-0091-5cd9-9250-8f819b40d9b5",
      "id": "CVE-2017-9735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-9735 is fixed in version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b8e096f-2c6f-5d33-a6cd-686e30ed9c4d",
      "id": "CVE-2018-12536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12536 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb0e85d-1fa8-5fd7-9513-8226ef0eada6",
      "id": "CVE-2018-12538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12538 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e7b30ee-5917-5e17-adcd-287a583cf161",
      "id": "CVE-2018-12545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12545 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efda8536-3c20-550b-b224-48b67bf80cb8",
      "id": "CVE-2019-10241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10241 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece72ae4-7ee0-54c2-b4ac-4e993e297ba2",
      "id": "CVE-2019-10246",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10246 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:629c6667-c1c2-5d46-ac29-03399f5fb968",
      "id": "CVE-2019-10247",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10247 is fixed in version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67ad137a-34a2-53c6-96bb-be538543e417",
      "id": "CVE-2019-17638",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-17638 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddacbe19-2eba-59b0-91cc-46e0d1057121",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-27216 is fixed in version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b35dbf-9a42-5bb7-b2b5-17134f8ee16f",
      "id": "CVE-2020-27218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27218 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8f8de03-c69a-59ed-94de-000e49fe77d6",
      "id": "CVE-2021-28165",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-28165 is a false positive for org.eclipse.jetty.tests:test-integration 8.2.0.v20160908-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36def0ed-462d-58c4-8588-b550b63c3d29",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-28169 is a false positive for org.eclipse.jetty.tests:test-integration 8.2.0.v20160908-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae91f03-a80d-55f8-95e5-d33414b3e795",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34428 is fixed in version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7399fde-e16b-5017-95c8-3e9132768656",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa8b8c0a-bd6d-5683-8ca2-ee79b9b08cc5",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-2048 is a false positive for org.eclipse.jetty.tests:test-integration 8.2.0.v20160908-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:100aa68f-f7f0-5f02-a8fd-b01f05e102d3",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26048 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52bd1a63-83cc-5174-a70f-ff08319b1b97",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26049 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b39b144-2c73-5c27-b0a2-367c398f8410",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a0819f6-a540-5d18-84c0-5bf59c1048a1",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40167 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. Version 8.2.0.v20160908 is not vulnerable. Summary: The target repository (Jetty 8.2.0.v20160908) is NOT vulnerable to CVE-2023-40167. Unlike newer Jetty versions (9.x+) that use Long.parseLong() for Content-Length parsing, this version uses BufferUtil.toLong() which correctly rejects the '+' prefix as per RFC 9110. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db4e1166-6775-5983-a730-d0f52776ea5d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-44487 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. The version is not vulnerable. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8945cc3f-3609-59f6-82be-ed21dd9f08da",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-13009 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe7a52e0-01fa-520d-9e4e-c6a5d47e2e8e",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6762 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. Version 8.2.0.v20160908 is not vulnerable. Summary: CVE-2024-6762 does not affect the target repository. The vulnerable classes PushCacheFilter and PushSessionCacheFilter are not present in Jetty 8.2.0.v20160908. These HTTP/2 Server Push filters were introduced in later versions (Jetty 9.x+) and do not exist in Jetty 8.x. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8233bbc-2285-5b96-a9c8-2cd7e81882a5",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84168ab8-333c-57d7-964d-4c620bccaae0",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. Version 8.2.0.v20160908 is not vulnerable. Summary: The target repository (Jetty 8.2.0.v20160908) does not contain the ThreadLimitHandler class that is affected by CVE-2024-8184. This vulnerability is specific to ThreadLimitHandler.getRemote() which was introduced in later versions of Jetty (likely 9.4.x or later). Since the vulnerable component does not exist in this older version, the target is not affected by this CVE. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64a375c8-e848-5ba1-b7c5-0395f3a98a59",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66985b71-052f-5897-9620-03437f7db067",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71fae3d9-0f11-58ed-9f02-5eac4574fa35",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. not_affected \u2014 Jetty 8.2.0 does not support HTTP trailers at all, so the trailer cross-request leakage vulnerability cannot manifest. The HttpParser immediately completes message processing upon encountering the final chunk without parsing the trailer-part section, and no trailer-related fields, methods, or APIs exist in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c935cf11-ff9b-5bc7-8a08-2562b30e3305",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. Version 8.2.0.v20160908 is not vulnerable. Summary: Target repository is Jetty 8.2.0.v20160908, which does not have the HTTP request decompression feature that contains CVE-2026-1605. The vulnerability only affects Jetty 12.0.0-12.0.31 and 12.1.0-12.1.5. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80423ee2-9c86-51f6-adfd-0998ddb98882",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8fe4094-8ef6-5c3d-b132-8021b7b1ec35",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b978eb2-5e73-5747-a68d-217874d33b96",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-6790 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. not_affected \u2014 Jetty 8.2.0.v20160908 does not implement HTTP/2 or HTTP/3, which are required to receive the CVE's attack INPUT (HTTP/2 or HTTP/3 request with mismatched :authority and Host headers). The target only supports HTTP/1.1 and SPDY (v2 and v3). SPDY uses :host pseudo-header, not :authority, and is architecturally different from HTTP/2. The vulnerability cannot manifest in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bc38c46-5f42-5138-85dd-3b262600c9d7",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration. not_affected \u2014 Jetty 8.2.0.v20160908 is not affected by CVE-2026-8384. The vulnerability requires a specific architectural pattern present in Jetty 12.x where path parameter stripping and path normalization occur in a single forward-scanning pass within canonicalPath(). Jetty 8.2.0 uses a fundamentally different two-stage architecture: HttpURI parsing strips path parameters by setting the _param boundary (eve..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6661b5e5-5885-5486-a563-c0a745423e30",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 8.2.0.v20160908-tuxcare.1 of org.eclipse.jetty.tests:test-integration."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.tests/test-integration@8.2.0.v20160908-tuxcare.1"
    }
  ]
}