{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7470202-5d42-58d5-aece-05d495306fe4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "infinispan-remote-query",
      "version": "9.4.48.v20220622-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:91c44608-449f-56ab-9e2e-a260a070ef81",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef86650-0869-578a-80a8-4932000c87e8",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaaa1c62-e676-52cf-822d-f7cd71b1a62f",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb3dba74-6ccb-5bb3-a7da-22887f06d3b5",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:572c4e76-cdbd-5723-a91a-c38b7337e3bc",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ac24f2e-f6b3-5fca-a7b6-297384a34a6d",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35bc8a9-7509-5074-a66e-d19455c68eda",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36a6cb6-acba-5637-8cab-1cfd2665094c",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6df46f-043c-52c3-9606-95f14101b1ca",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eea83f0-9e6f-5a2b-968a-b66d1e7ce2ac",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752c5c8f-f6b9-5f14-9a14-7e7c971dfa9d",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6fd5f30-9efa-5748-a3fa-6eb991e2c04f",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12755644-ce3f-58a2-b67b-7354abcc87b6",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d4b5a7-ba3a-539b-a693-367326f5e478",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:047eee18-69c7-5886-8ff2-9bfc906f6d4a",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ccf14cf-876e-59fc-a203-df5cb2ea0ddb",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35fdc39a-1c2e-5080-866f-3b80473f707e",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b51a7d-78d5-558b-a4b1-38624e09880a",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c0e562-1779-55a0-979d-eb7d57a5ca5d",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb996ca9-aa6d-58d7-b4f1-2abf3bded387",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query. not_affected \u2014 CVE-2026-10051 describes an HTTP/1.1 keep-alive connection trailer cross-request leakage vulnerability in Jetty 12.x where the connection-scoped `_trailers` field is never reset between requests. The target Jetty 9.4.48.v20220622 has a different architecture (HttpChannelOverHttp + HttpChannel vs Jetty 12's HttpConnection internal structure) and already contains an upstream vendor fix from July ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7513d41e-2f3c-5258-8a45-d96f76a8724d",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query. Version 9.4.48.v20220622 is not vulnerable. Summary: Target repository is Jetty 9.4.48.v20220622-tuxcare.1, which is not in the affected version range. CVE-2026-1605 specifically affects Jetty 12.0.0-12.0.31 and 12.1.0-12.0.5. The architectures are fundamentally different between these major versions. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d648356-4a0d-501c-a82e-e9e2fe5a0a9a",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c90f6480-4df8-5554-937a-c22b6ab40069",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52cccc5b-9784-5336-93f2-e648f2d48c91",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3647967a-e99f-5352-aa48-f96b1230bb6f",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query. not_affected \u2014 Jetty 9.4.48.v20220622 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.1.8 where canonicalPath() has a semicolon-handling case that fails to update character-tracking state, breaking dot-segment detection. Version 9.4.48 uses a different architecture where canonicalPath() does not have explicit semicolon handling - semicolons are treated as regular characters in the defau..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11258711-45dc-5072-84ca-35090c321e50",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.48.v20220622-tuxcare.2 of org.eclipse.jetty:infinispan-remote-query."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/infinispan-remote-query@9.4.48.v20220622-tuxcare.2"
    }
  ]
}