{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:687ba6ad-ac0e-53ba-b8d1-e8a54d71756c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-alpn-java-client",
      "version": "9.4.50.v20221201-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:96bc4349-72fa-5c58-9a53-89167d18e20b",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a322fd0-b89a-58f7-8f69-737ecf368f82",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0365d4-1991-5c25-b10e-28d43badb2a8",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e4af25-1e35-5b72-91b5-84b195c5b66c",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client. Version 9.4.50.v20221201 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f7c45eb-d9f4-5ff4-a1a4-1587cebcd91c",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01570079-d8b8-5c32-8d55-f1515c5a6fec",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01792b4f-a105-5264-92f8-adb3eac81ef2",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef26261-11be-5bb1-a626-067d22cb1877",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:401e02ff-5cab-5e3d-bc6e-13c613793221",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e30c367b-5b3c-5ccc-9aa6-36cfc6e4c950",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95ca3fc-0e6e-5f44-8d17-60b13ac46f0d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0566cca9-e20d-5aa5-969f-ff0ef4a058a8",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665860ca-d766-5c19-95f6-ee93f7806e9e",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ec65669-2626-5ce2-8b4c-fcc0d1e34238",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac2c473-c5d3-5edb-9972-fbaad9c34d98",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0924b17e-6442-5525-bff8-aabf82ea4d4e",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d878239c-03e3-5fae-9c3f-fe175a0b0c2e",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ecd7c6-d9d6-5840-83b3-a20205dc343a",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012ab2f6-1d58-54cb-830b-d6463d3a19d7",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a138dc-3d30-5e4c-b9f7-7f0f73b958ad",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea53e6f-a202-5ea3-a593-5cdd35fd72bc",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92055ca9-da64-53eb-9542-3b082b1ddcd9",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:430ea171-bcbc-50e6-bef7-3ccffcedbf46",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52a2ea7c-a9aa-58ac-a938-68cbafe3f106",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1f69363-7f80-58de-a81f-2d60fe242a43",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315c6942-e47d-53f9-9df8-368d42fa1abb",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc0f5a5-5383-5b35-a7da-4c815af9c44a",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-alpn-java-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-alpn-java-client@9.4.50.v20221201-tuxcare.3"
    }
  ]
}