{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:050fb6cb-b31e-536e-bbd7-1cc3143e4617",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "infinispan-common",
      "version": "9.4.58.v20250814-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9db60cfd-631a-5ae7-a830-ad94d5fe13a6",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1dbd8f7-f625-5000-ab05-a6125c47197d",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f2bbf0f-fba8-5828-852a-2e4ba482953e",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd1c2b20-375d-5e85-b1fb-ce77e8ac16db",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f7b5845-38f0-50d8-bd4e-8a1d4f8fe343",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:023eb7be-5ccf-589d-86fd-40653772aba1",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519ac511-4f1c-5e09-961d-c076098662c0",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4007e7f6-ff1b-5701-8409-6a5121a10887",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6df43c78-e9c8-5b34-b508-27c8d1e39b7d",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c64de63-32e8-52a0-89dc-7bdd72b2c837",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:265aede6-adea-5681-9435-156b1669544d",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01073e6-6586-56ac-a833-f778c686cbe9",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99898acf-3413-5c1c-af47-713aee737751",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed87bd82-f996-54c2-80c6-af1a5d90c5bc",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5d6332-9aed-528d-b595-37a9ac850fd2",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:032d632f-4823-5753-b9b5-083bda7692be",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c9cb03c-796f-5f9f-8948-5ec7d4a51d60",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5142d2df-e4f7-5047-88bf-a29f692d9090",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e50580-216c-5509-ac93-4bc4a457bda6",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77cf1c8c-ccb5-5e97-963d-54452eceaafc",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c727e7cd-d6a8-572e-a504-0d6328826a76",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.3 of org.eclipse.jetty:infinispan-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/infinispan-common@9.4.58.v20250814-tuxcare.3"
    }
  ]
}