{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cb7e419d-6d44-5145-bbe1-e42531ac8a9d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-hazelcast",
      "version": "9.4.50.v20221201-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5e06f346-3317-5bdd-9811-f57411db9b47",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de527f2-1680-5a61-9287-27bbc09aa3be",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b6d2794-2f6c-5345-9588-d116b9ac15b6",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d4c2f0-0fff-5ce2-ba8c-9decd9cc0fba",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast. Version 9.4.50.v20221201 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4843b2f-c389-525f-aed1-5b8514b19587",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:109916c6-6c09-5022-adab-86d4d289629e",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f81f7c-007c-55d2-be03-cb5389358ec5",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a1d9fa-a06e-5c55-b641-ff0b9af9b90e",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:052a0155-83a7-54f4-afba-f2f91db2edd8",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb65e36-1509-5ec2-ae50-d06a3e5b6cfd",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ece8026-f0a9-5749-affb-ea7d1c7e23bf",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f4685d-37c5-5020-b2eb-dd8444abd7aa",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:339ed2bd-2c31-5969-8922-666833779b74",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96c0fc9c-1e59-51cc-82b4-8169c07c9d1b",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce68e831-1e8c-5613-916e-b839407d64bb",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15753fdf-e3dc-5da3-b15a-a9357d194b7a",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600db3da-1bb9-5d48-b8d5-ec047fb5944a",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82920e7e-07e5-56a1-abad-e33cba46dea7",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c63701b-cf85-5cca-a019-018a59481a30",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b47a9bc-c4a5-5a00-82b0-41980504c6fb",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c567277b-7118-595d-8d6e-07627b798f28",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257765a0-7c9b-5760-a177-cd28277d9198",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a94bcfcf-7d7d-58db-b691-2b7efeaadbae",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80f1de6-a701-5487-aa0f-671912c2e0d8",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5e8a7c0-181a-5955-82ed-55427b0b98f3",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e50ced0-08fb-5b65-92de-6915aa5d5c69",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b80e15-2087-53a2-a10b-dca691ba2da9",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-hazelcast."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-hazelcast@9.4.50.v20221201-tuxcare.3"
    }
  ]
}