{
  "@id": "urn:uuid:68d698f0-f69b-4f3a-8335-e37af6c67e31",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-27216 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.60 is not vulnerable. Summary: The target repository at version 9.4.60 is NOT vulnerable to CVE-2020-27216. The vulnerability was a race condition in temporary directory creation that could lead to local privilege escalation on Unix-like systems. The fix was introduced in version 9.4.33.v20201020 (released October 20, 2020) by replacing the vulnerable File.createTempFile() + delete() + mkdir() pattern with the secure Files.createTempDirectory() method. The current [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-27216"
      },
      "impact_statement": "Version 9.4.60 is not vulnerable. Summary: The target repository at version 9.4.60 is NOT vulnerable to CVE-2020-27216. The vulnerability was a race condition in temporary directory creation that could lead to local privilege escalation on Unix-like systems. The fix was introduced in version 9.4.33.v20201020 (released October 20, 2020) by replacing the vulnerable File.createTempFile() + delete() + mkdir() pattern with the secure Files.createTempDirectory() method. The current [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-28169 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The ConcatServlet now properly validates paths before dispatching, preventing double-encoded path traversal attacks to access WEB-INF/META-INF protected resources. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-28169"
      },
      "impact_statement": "Version 9.4.60 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The ConcatServlet now properly validates paths before dispatching, preventing double-encoded path traversal attacks to access WEB-INF/META-INF protected resources. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-34428 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.60 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed.",
      "vulnerability": {
        "name": "CVE-2021-34428"
      },
      "impact_statement": "Version 9.4.60 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36478 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.59 is not vulnerable. Summary: The target repository has all security fixes from CVE-2023-36478 already applied. The repository is NOT vulnerable to the integer overflow attack in HTTP/2 HPACK header processing. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2023-36478"
      },
      "impact_statement": "Version 9.4.59 is not vulnerable. Summary: The target repository has all security fixes from CVE-2023-36478 already applied. The repository is NOT vulnerable to the integer overflow attack in HTTP/2 HPACK header processing. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-36479 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2023-36479"
      },
      "action_statement": "Vulnerability CVE-2023-36479 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-40167 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2023-40167"
      },
      "action_statement": "Vulnerability CVE-2023-40167 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41900 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2023-41900"
      },
      "action_statement": "Vulnerability CVE-2023-41900 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-22201 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2024-22201"
      },
      "action_statement": "Vulnerability CVE-2024-22201 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6762 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2024-6762"
      },
      "action_statement": "Vulnerability CVE-2024-6762 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-6763 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-6763"
      },
      "impact_statement": "fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-8184 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.60 is not vulnerable. Summary: The target repository (Jetty 9.4.60.tuxcare0001) already has the CVE-2024-8184 fix applied. The ThreadLimitHandler uses atomic reference counting with ConcurrentHashMap.compute() methods instead of the vulnerable get+putIfAbsent pattern. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2024-8184"
      },
      "impact_statement": "Version 9.4.60 is not vulnerable. Summary: The target repository (Jetty 9.4.60.tuxcare0001) already has the CVE-2024-8184 fix applied. The ThreadLimitHandler uses atomic reference counting with ConcurrentHashMap.compute() methods instead of the vulnerable get+putIfAbsent pattern. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-11143 is fixed in version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2025-11143"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-5115 is fixed in version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2025-5115"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10050 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2026-10050"
      },
      "action_statement": "Vulnerability CVE-2026-10050 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-10051 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2026-10051"
      },
      "action_statement": "Vulnerability CVE-2026-10051 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-1605 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2026-1605 does not apply to Jetty 9.4.60. The vulnerability is specific to Jetty 12.x architecture which uses different classes and lifecycle management. [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-1605"
      },
      "impact_statement": "Version 9.4.60 is not vulnerable. Summary: CVE-2026-1605 does not apply to Jetty 9.4.60. The vulnerability is specific to Jetty 12.x architecture which uses different classes and lifecycle management. [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-2332 is fixed in version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2026-2332"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-5795 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2026-5795"
      },
      "action_statement": "Vulnerability CVE-2026-5795 affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-6790 is fixed in version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "CVE-2026-6790"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-8384 does not affect version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent. not_affected \u2014 Jetty 9.4.60 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.1.8's URIUtil.canonicalPath() method which combines decoding and normalization in one operation with a slash-state tracking bug. Jetty 9.4.60 uses a different two-phase architecture where URIUtil.decodePath() strips semicolons first, then URIUtil.canonicalPath() normalizes dot segments on the decoded path. The s...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-8384"
      },
      "impact_statement": "not_affected \u2014 Jetty 9.4.60 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.1.8's URIUtil.canonicalPath() method which combines decoding and normalization in one operation with a slash-state tracking bug. Jetty 9.4.60 uses a different two-phase architecture where URIUtil.decodePath() strips semicolons first, then URIUtil.canonicalPath() normalizes dot segments on the decoded path. The s..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-parent@9.4.60.tuxcare0003"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent.",
      "vulnerability": {
        "name": "GHSA-58qw-p7qm-5rvh"
      },
      "action_statement": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.60.tuxcare0003 of org.eclipse.jetty.websocket:websocket-parent."
    }
  ]
}
