{
  "@id": "urn:uuid:57a68f4e-2016-4397-a4cf-b0df67d2e2b4",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2017-12196 does not affect version 1.4.27.Final-tuxcare.1 of io.undertow:karaf. not_affected \u2014 CVE-2017-12196 is an Undertow Digest-auth flaw: the server failed to verify that the \"digest-uri\" value inside the Authorization header matches the actual HTTP request-line URI, enabling a MITM/credential-reuse attack (a captured Digest credential could be redirected to a different resource). Fixed upstream in 1.4.24.Final (UNDERTOW-1190). The target is undertow 1.4.27.Final (tuxcare.1 backport), which is AFTER the fix version. Direct code inspection confirms the fix is present: DigestAuthenticationMechanism.handleDigestHeader() (core/.../security/impl/DigestAuthenticationMechanism.java:233-257) compares the Authorization \"digest-uri\" token against the reconstructed request URI (path + \"?\" + query) and, as an enhancement, against the absolute request URL; on mismatch it sets 400 BAD_REQUEST and ends the exchange without authenticating, and if the DIGEST_URI token is absent it returns NOT_AUTHENTICATED. The check is on the sole Digest execution path (authenticate() -> handleDigestHeader(), line 167) and precedes credential (H(A2)) validation, with no bypass. git blame attributes lines 233-239 to upstream commit c916239d and lines 240-254 to upstream commit 11b6f0e0, both by Stuart Douglas (stuart.w.douglas@gmail.com). Both commits are ancestors of the plain upstream 1.4.27.Final commit, so the fix shipped upstream before TuxCare onboarding. Verdict: not_affected (upstream fix already present; not a TuxCare backport, so not \"already_fixed\"). [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2017-12196"
      },
      "impact_statement": "not_affected \u2014 CVE-2017-12196 is an Undertow Digest-auth flaw: the server failed to verify that the \"digest-uri\" value inside the Authorization header matches the actual HTTP request-line URI, enabling a MITM/credential-reuse attack (a captured Digest credential could be redirected to a different resource). Fixed upstream in 1.4.24.Final (UNDERTOW-1190). The target is undertow 1.4.27.Final (tuxcare.1 backport), which is AFTER the fix version. Direct code inspection confirms the fix is present: DigestAuthenticationMechanism.handleDigestHeader() (core/.../security/impl/DigestAuthenticationMechanism.java:233-257) compares the Authorization \"digest-uri\" token against the reconstructed request URI (path + \"?\" + query) and, as an enhancement, against the absolute request URL; on mismatch it sets 400 BAD_REQUEST and ends the exchange without authenticating, and if the DIGEST_URI token is absent it returns NOT_AUTHENTICATED. The check is on the sole Digest execution path (authenticate() -> handleDigestHeader(), line 167) and precedes credential (H(A2)) validation, with no bypass. git blame attributes lines 233-239 to upstream commit c916239d and lines 240-254 to upstream commit 11b6f0e0, both by Stuart Douglas (stuart.w.douglas@gmail.com). Both commits are ancestors of the plain upstream 1.4.27.Final commit, so the fix shipped upstream before TuxCare onboarding. Verdict: not_affected (upstream fix already present; not a TuxCare backport, so not \"already_fixed\"). [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-1114 does not affect version 1.4.27.Final-tuxcare.1 of io.undertow:karaf. not_affected \u2014 Target is Undertow 1.4.27.Final (undertow-io/undertow) \u2014 correct product, not a false positive. CVE-2018-1114 is the file-descriptor leak where URLResource.getLastModified()/getContentLength() opened a URLConnection but closed the underlying stream only at GC finalization, exhausting file descriptors (DoS). The complete upstream fix is already present in the shipped 1.4.27.Final source. URLResource.openConnection() (core/.../resource/URLResource.java:80-110) closes the connection's input stream promptly in a finally block (IoUtils.safeClose(connection.getInputStream()), lines 100-108) and, for jar: URLs, disables caching and reads the timestamp from the underlying jar file directly (setUseCaches(false) + File.lastModified(), lines 92-98) \u2014 exactly the change in the provided patch commits 882d5884/7f22aa0090. git blame attributes these lines to upstream commits 87f4fb41fc (UNDERTOW-1081, 2017-05-24) and 7f22aa0090 (UNDERTOW-1338, 2018-04-24), both ancestors of HEAD, both predating the 1.4.27.Final release. The vulnerable close-on-finalization pattern is therefore absent from HEAD. The fix is upstream-authored (stuart.w.douglas@gmail.com / norito.agetsuma@gmail.com), NOT a TuxCare/CloudLinux backport, and URLResource.java was not modified after onboarding \u2014 so verdict is not_affected (vendor fix already shipped), justification code_not_present. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2018-1114"
      },
      "impact_statement": "not_affected \u2014 Target is Undertow 1.4.27.Final (undertow-io/undertow) \u2014 correct product, not a false positive. CVE-2018-1114 is the file-descriptor leak where URLResource.getLastModified()/getContentLength() opened a URLConnection but closed the underlying stream only at GC finalization, exhausting file descriptors (DoS). The complete upstream fix is already present in the shipped 1.4.27.Final source. URLResource.openConnection() (core/.../resource/URLResource.java:80-110) closes the connection's input stream promptly in a finally block (IoUtils.safeClose(connection.getInputStream()), lines 100-108) and, for jar: URLs, disables caching and reads the timestamp from the underlying jar file directly (setUseCaches(false) + File.lastModified(), lines 92-98) \u2014 exactly the change in the provided patch commits 882d5884/7f22aa0090. git blame attributes these lines to upstream commits 87f4fb41fc (UNDERTOW-1081, 2017-05-24) and 7f22aa0090 (UNDERTOW-1338, 2018-04-24), both ancestors of HEAD, both predating the 1.4.27.Final release. The vulnerable close-on-finalization pattern is therefore absent from HEAD. The fix is upstream-authored (stuart.w.douglas@gmail.com / norito.agetsuma@gmail.com), NOT a TuxCare/CloudLinux backport, and URLResource.java was not modified after onboarding \u2014 so verdict is not_affected (vendor fix already shipped), justification code_not_present. [VC re-run with claude-opus-4-8, prod prompt pin d46bd7a, 2026-09-16; Sonnet run failed the author gate (A2 onboarding-merge overclaim); applied manually after git verification]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2018-14642 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2018-14642"
      },
      "action_statement": "Vulnerability CVE-2018-14642 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-10184 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2019-10184"
      },
      "action_statement": "Vulnerability CVE-2019-10184 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-10212 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2019-10212"
      },
      "action_statement": "Vulnerability CVE-2019-10212 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-14888 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2019-14888"
      },
      "action_statement": "Vulnerability CVE-2019-14888 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-19343 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2019-19343"
      },
      "action_statement": "Vulnerability CVE-2019-19343 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2019-3888 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2019-3888"
      },
      "action_statement": "Vulnerability CVE-2019-3888 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-10687 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-10687"
      },
      "action_statement": "Vulnerability CVE-2020-10687 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-10705 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-10705"
      },
      "action_statement": "Vulnerability CVE-2020-10705 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-10719 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-10719"
      },
      "action_statement": "Vulnerability CVE-2020-10719 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-1745 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-1745"
      },
      "action_statement": "Vulnerability CVE-2020-1745 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-1757 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-1757"
      },
      "action_statement": "Vulnerability CVE-2020-1757 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-27782 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2020-27782"
      },
      "action_statement": "Vulnerability CVE-2020-27782 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-20220 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2021-20220"
      },
      "action_statement": "Vulnerability CVE-2021-20220 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3597 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2021-3597"
      },
      "action_statement": "Vulnerability CVE-2021-3597 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3629 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2021-3629"
      },
      "action_statement": "Vulnerability CVE-2021-3629 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3690 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2021-3690"
      },
      "action_statement": "Vulnerability CVE-2021-3690 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-3859 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2021-3859"
      },
      "action_statement": "Vulnerability CVE-2021-3859 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-1259 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2022-1259"
      },
      "action_statement": "Vulnerability CVE-2022-1259 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-1319 does not affect version 1.4.27.Final-tuxcare.1 of io.undertow:karaf. Version 1.4.27.Final is not affected by CVE-2022-1319. The vulnerability was introduced in UNDERTOW-1824 (Oct 2020) when the handleBadRequest() method and related AJP response constants were added to versions 2.2.x and later. Version 1.4.27.Final (Jan 2019) predates this change and uses a simpler response mechanism that only calls httpServerExchange.endExchange() once without manual AJP packet generation, making the double-response vulnerability pattern impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2022-1319"
      },
      "impact_statement": "Version 1.4.27.Final is not affected by CVE-2022-1319. The vulnerability was introduced in UNDERTOW-1824 (Oct 2020) when the handleBadRequest() method and related AJP response constants were added to versions 2.2.x and later. Version 1.4.27.Final (Jan 2019) predates this change and uses a simpler response mechanism that only calls httpServerExchange.endExchange() once without manual AJP packet generation, making the double-response vulnerability pattern impossible."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-2053 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2022-2053"
      },
      "action_statement": "Vulnerability CVE-2022-2053 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-4492 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2022-4492"
      },
      "action_statement": "Vulnerability CVE-2022-4492 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-1108 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2023-1108"
      },
      "action_statement": "Vulnerability CVE-2023-1108 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-1973 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2023-1973"
      },
      "action_statement": "Vulnerability CVE-2023-1973 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-3223 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2023-3223"
      },
      "action_statement": "Vulnerability CVE-2023-3223 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-4639 is fixed in version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2023-4639"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1459 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-1459"
      },
      "action_statement": "Vulnerability CVE-2024-1459 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-1635 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-1635"
      },
      "action_statement": "Vulnerability CVE-2024-1635 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3653 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-3653"
      },
      "action_statement": "Vulnerability CVE-2024-3653 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-3884 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-3884"
      },
      "action_statement": "Vulnerability CVE-2024-3884 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-4027 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-4027"
      },
      "action_statement": "Vulnerability CVE-2024-4027 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-5971 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-5971"
      },
      "action_statement": "Vulnerability CVE-2024-5971 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6162 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-6162"
      },
      "action_statement": "Vulnerability CVE-2024-6162 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-7885 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2024-7885"
      },
      "action_statement": "Vulnerability CVE-2024-7885 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-12543 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2025-12543"
      },
      "action_statement": "Vulnerability CVE-2025-12543 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-9784 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2025-9784"
      },
      "action_statement": "Vulnerability CVE-2025-9784 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28367 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2026-28367"
      },
      "action_statement": "Vulnerability CVE-2026-28367 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28368 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2026-28368"
      },
      "action_statement": "Vulnerability CVE-2026-28368 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-28369 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2026-28369"
      },
      "action_statement": "Vulnerability CVE-2026-28369 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/io.undertow/karaf@1.4.27.Final-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-3260 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf.",
      "vulnerability": {
        "name": "CVE-2026-3260"
      },
      "action_statement": "Vulnerability CVE-2026-3260 affects version 1.4.27.Final-tuxcare.1 of io.undertow:karaf."
    }
  ]
}
