{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b1c2e4fe-2602-51f4-845c-9bb0114f6f9d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-util",
      "version": "9.4.50.v20221201-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2279e502-2142-5c59-ac1a-1dddb47ca203",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0b615b-d9c8-5c3d-9a3b-5454264465d6",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8301774f-4a95-5c36-b754-d8e05e9f908d",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fedaa7c2-bb66-5c78-98a0-821cefedd641",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:569dbcee-2115-5888-a538-2b794f068331",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:326c895d-8a8e-582a-b90a-54a7c842a58b",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19d9c183-b978-5785-ae48-0fe43d7190c0",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a37ae72-ea0d-57d7-8ea4-1331d997a70b",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a06c3a-8ca9-54eb-a336-24e2c85b3ae0",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:710748a4-c295-5d3a-aa88-ee9e1e4e0f57",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1349905-1515-540c-aa22-5fa04776a596",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fe6335a-0e83-5d98-b38d-719aae1f7b5f",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be05bf67-b16c-5ff2-99c2-e1fbd95ed86f",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:314b395b-198d-5d25-874d-eaddd2ef4849",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a36197-fac0-5984-8acc-c504b66eb051",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8465d028-13d4-5fea-bbca-6d66e1ff7d21",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab8a3ed5-265d-5bcc-8eeb-cd83940bbd03",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a899260c-974a-5abe-b9f8-ede4a4bddb21",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c01302-c1bd-599d-b192-36f9689694b5",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5953cfc1-8ac1-57cb-a2b6-6c125d6eecb2",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d0c6f18-a4a6-5010-951f-53e1810ea211",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b5927f1-5b94-5ca0-a172-35b0b887afbf",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5ef8f24-6714-5479-bb86-3cbb896a17ed",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7d05375-478e-5aa8-aaf4-983557343c12",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55da649-6cc3-5e5d-b6bd-abacb9de10da",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7bca7e-27a8-5a9a-aaa3-1fa03397eec1",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:784a3745-0fc3-52a0-8728-a4d5bb9b9d82",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.2 of org.eclipse.jetty:jetty-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-util@9.4.50.v20221201-tuxcare.2"
    }
  ]
}