{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:124e5c14-5846-5eae-b41d-e0af83c67c8a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-bom",
      "version": "9.4.41.v20210516-tuxcare.4",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c7fd078d-a235-56ca-bc96-b30af7ac93e7",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef08966-fd44-52d9-bfe5-33282ea62cd5",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom. Version 9.4.41.v20210516 is not vulnerable. Summary: The target repository (Jetty 9.4.41.v20210516) has the fix for CVE-2021-28169 applied. The vulnerability allowed doubly-encoded paths like '/%2557EB-INF/web.xml' to bypass security checks and access protected WEB-INF resources. The fix (commit 1c05b0bcb18) changed ConcatServlet.java line 130 to pass the original undecoded query parameter to RequestDispatcher instead of the decoded path, allowing the dispatcher's security me [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c4eee3-1bda-5753-b806-efc512c10d4b",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:723892d2-fe07-5606-a0be-6d6cd3ff8845",
      "id": "CVE-2021-34429",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34429 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a158d0-8342-53a3-917d-edc944caa5c4",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dced804-e930-5a59-b652-768e76c1141f",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2048 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f68f28-7d49-5aad-bbb9-0dd306cfa0ae",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26048 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd754d78-f3f7-5088-b1fd-86d7365425eb",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:094a4edc-035e-59e9-bc20-52bfa6e6c8f8",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33923bfb-c249-5486-84f1-aed5672d23eb",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05c569b2-4c49-52f9-b23a-af2e420f49e2",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40167 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046dcf2c-85b3-594a-a689-7fd1494178ad",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3869fa9-30a8-5847-9139-2bc4592c5b0b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58547cbe-3fd4-5e9d-9d2a-9d1883bed6e3",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-13009 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1bddadd-3189-5dd8-a15b-9ee275301c65",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6068f8c9-f46c-564c-a5d8-5d08643655ea",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22ae2311-bdac-5035-9712-05e75364a858",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:081bc26c-23fd-54d8-9166-7babc43d6295",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb534cf-9b24-56c9-ab76-6d2cb6f7555c",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-9823 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d3806d-0205-5d1d-95ed-4b737064aa25",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fe8fea6-7c9a-5341-8b3a-353f1bd0f91e",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d07ce03-3907-5316-8b9d-ffd3aba9baa1",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c797aa0-0320-51e6-b457-26dffe8a2085",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom. not_affected \u2014 Jetty 9.4.41.v20210516 is not affected by CVE-2026-10051. The vulnerability describes HTTP request trailer cross-request leakage in Jetty 12.x where the _trailers field was not reset between requests. However, Jetty 9.4.41 already contains the fix from upstream commit be1eb26670 (July 2017, Simone Bordet), which properly resets _trailers to null in the recycle() method called after each request..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04539e9f-f5b1-5117-9475-afb58ca8d15a",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom. Version 9.4.41.v20210516 is not vulnerable. Summary: Target repository is Jetty 9.4.41.v20210516, which is outside the affected version range (12.0.0-12.0.31 and 12.1.0-12.0.5) and has a fundamentally different architecture that does not contain the vulnerable code patterns. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acbc9025-00a9-58ac-995a-dc3979ad54bb",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea632799-a843-5162-99af-f8eaf9512628",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b142ac49-e16d-5eaa-b41c-234bf778cf94",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom. not_affected \u2014 Jetty 9.4.41.v20210516 is not affected by CVE-2026-8384. The target version includes upstream fixes from February 2021 (issue #4275, commits 20ef71fe5d7 and f9b5974dedf) that add ambiguous URI path parameter checking. These fixes prevent exploitation of the semicolon-followed-by-dot-segment pattern described in the CVE by rejecting such URIs with a BadMessageException before they reach security..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b55555ef-e20e-52b0-94c4-81ee8770b596",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.41.v20210516-tuxcare.4 of org.eclipse.jetty:jetty-bom."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-bom@9.4.41.v20210516-tuxcare.4"
    }
  ]
}