{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8c3a78dc-24bc-5b7e-8de6-659d2b7e8667",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-plus",
      "version": "9.4.50.v20221201-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d47674a9-2c58-5da0-8df1-976e6df8ecdd",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7057d9f6-8b40-5ab9-8b37-875b8f4fc849",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b516ebc4-0ed5-568d-b7af-748c533179f4",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b11debd-5aeb-5a35-8352-93a34c2d2dad",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus. Version 9.4.50.v20221201 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d58a9a3d-fb3d-5f16-bb6c-4acb694e2990",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:323c67a8-f1c8-5cb0-bad3-561c83c15758",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:137cf814-dea4-51da-b49d-cb0cd7fb7888",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba19c54b-dcec-526d-b98e-3e73069ac0de",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3843f1a2-46ab-59aa-8306-c1404fe26a37",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f668bd7-bd64-58e0-a23c-5506e4fad515",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ec2627-c347-573b-b45a-fa2393e214be",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd3b14e-769d-59d5-a84d-aec89f6d3d56",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e940385b-0346-5561-93e4-17c36dd0340e",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6866a725-bbd0-56a8-8568-aad7c10794cc",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc07fc17-33fc-575f-b2a4-9dfa7d3006c8",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef36249-9d5f-516f-88ae-c4a220f1d5cb",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6aa75ec-5117-51fe-9db6-ca04a08611d0",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78c135b1-5b3b-51f2-8936-23afd576563b",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f40226fd-88fe-50d1-a093-d76141baf37b",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287a4743-d3df-579c-b9c7-3c98d7e5831c",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b99602e7-0e25-57df-96c7-d45072a86e06",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c3afe7-34aa-50e8-9c52-8fa44850a515",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69041e93-62aa-5661-b9c5-c800b04eea42",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf5c464-528f-5fa7-bbac-fc706561d6ef",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:678c9811-5e83-5cbb-8c3d-7cd2ca08f486",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:029233c3-8496-5560-bf7f-24f80979e5e2",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4fdfc83-ad78-505f-903c-d2b0a71e24b8",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-plus."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-plus@9.4.50.v20221201-tuxcare.3"
    }
  ]
}