{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3504985e-abfe-5900-8582-b340e6b9746e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-spring",
      "version": "9.4.50.v20221201-tuxcare.3",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c18129c5-2d2c-50a6-bd1f-b2b15bf2d163",
      "id": "CVE-2020-25711",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-25711 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f230874-dc02-57df-91ad-65297afea2c8",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbd729e8-3e12-5b36-915b-47b5d96c98a8",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce8a7a68-862e-5bc1-8e45-8b03b7d5fc32",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring. Version 9.4.50.v20221201 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4386f3ec-080e-5850-b577-6efdd282df72",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94630c25-c24e-5c4f-8c6e-d2cf2d9dbf21",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1d7c769-cd51-5ad9-b4d4-6365f4bfe2c2",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f5a559-8e7c-5e20-ada7-f4dce105d4f1",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6642b84e-df6c-56a8-b029-a391e9c1f2f2",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:545b279c-48aa-5f3c-8f91-71ce50ced8fb",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a993f29e-0313-5e30-9eee-23eae9fa8a23",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d19c630-afd5-5565-96b8-53f990717d36",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-13009 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c585064-e56f-5cfb-801c-5b81d91b8174",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1380f0db-0e2c-59fa-a29c-3eacc8477f5c",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be3c009-2d96-559e-ad28-16529eca3020",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d8e136-2c05-5beb-9c46-f9a5e899669e",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b78952-ddde-57a2-a1d3-3287b2990b65",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-9823 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f35f9a-4f05-5cf0-9216-f26a90f95c69",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa41ff67-0548-576c-8f96-3b9642568e90",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:042fc066-2766-51d1-a6ec-05695edc3bf1",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d4fe371-8efb-5eac-b4b0-6ea73baf0f6f",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-10051. While the CVE describes a cross-request trailer leakage vulnerability in Jetty 12+, this target version uses a different architecture where the fix has been present since July 2017 (commit be1eb26670f). The _trailers field is properly cleared in HttpChannel.recycle() (line 418) and HttpChannelOverHttp.recycle() (line 89), which are calle..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b66eafe5-d3a3-5861-a933-40c4c735333c",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring. Version 9.4.50.v20221201 is not vulnerable. Summary: Target repository is Jetty 9.4.50.v20221201, which predates the vulnerable Jetty 12.x architecture. CVE-2026-1605 specifically affects Jetty versions 12.0.0-12.0.31 and 12.1.0-12.1.5 with their new Content API and GzipRequest implementation. The target uses a completely different architecture for gzip request handling. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f869393d-3686-53ab-be9a-11c18e0f2a5b",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d31d5010-dc1c-524e-8a53-56c0111adfec",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1d6a50-abf2-5bd0-b31a-5cf22f9a1ff3",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bed34133-1382-5ddf-9f9c-ae93f1b72868",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring. not_affected \u2014 Jetty 9.4.50.v20221201 is not affected by CVE-2026-8384. While Jetty 12.x contains a vulnerability in combined semicolon-handling and path-normalization logic (where stale state tracking after processing `;/` prevents dot-segment detection), Jetty 9.4.50 uses a fundamentally different two-step architecture that eliminates this vulnerability class."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99cfe346-15e3-5c5f-8dfd-6463f0582fa2",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.50.v20221201-tuxcare.3 of org.eclipse.jetty:jetty-spring."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-spring@9.4.50.v20221201-tuxcare.3"
    }
  ]
}