{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:92a6c8e7-c0a5-557d-bffd-80add75933e2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-util-ajax",
      "version": "9.4.41.v20210516-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e2d4a92f-072c-5bc8-9e6e-84e9b789df54",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d5e043e-cb8d-508c-b6be-359a0fc597bd",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax. Version 9.4.41.v20210516 is not vulnerable. Summary: The target repository (Jetty 9.4.41.v20210516) has the fix for CVE-2021-28169 applied. The vulnerability allowed doubly-encoded paths like '/%2557EB-INF/web.xml' to bypass security checks and access protected WEB-INF resources. The fix (commit 1c05b0bcb18) changed ConcatServlet.java line 130 to pass the original undecoded query parameter to RequestDispatcher instead of the decoded path, allowing the dispatcher's security me [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbaf503d-48c6-5c2e-a007-e42af8804190",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb842823-ba20-5f16-9b36-44f1cd96e07a",
      "id": "CVE-2021-34429",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34429 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97ac9674-ecc2-5572-b8e0-525b05cf5350",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e52a1d5-a31b-5122-8d64-60f838e0f073",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-2048 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59931177-f395-55c0-a51a-bf8ef0f9e242",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26048 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ccad522-b9ad-5605-a737-e452de8371aa",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9970b5-f236-5102-828a-04e8aee6f84a",
      "id": "CVE-2023-36478",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3abc8054-d0c8-5ade-a1d8-5ee6bf8be0c5",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd217f14-fcaa-5a21-b497-08b063dec912",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e048093-6d37-5013-be64-7a9c4ec7b1ba",
      "id": "CVE-2023-41900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41900 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ea4287d-b26f-57a9-94b5-b80e7c5b1aa2",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7435724f-7d4c-5bad-b754-e04f901f5cf0",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-13009 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78489e79-5190-5765-b339-66b3228f2e5e",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22201 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc434d47-b65f-5e01-8072-4c2e603a803b",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6762 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3506862d-15cd-5618-82c4-e31ab552b6f5",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff943748-1951-567f-8ebf-879028da8165",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8184 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97be602a-cf5b-5ed1-9d0e-bca90834bbb6",
      "id": "CVE-2024-9823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-9823 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8898f008-e05d-5e1a-8c03-605f445e3701",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62ce69fc-b9ea-5571-a3a0-15e528d0897c",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a897ab6e-2cde-5b62-8876-fdf858d313f6",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803908db-8496-53d3-ba5d-cbb73814d283",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax. not_affected \u2014 Jetty 9.4.41.v20210516 is not affected by CVE-2026-10051. The vulnerability describes HTTP request trailer cross-request leakage in Jetty 12.x where the _trailers field was not reset between requests. However, Jetty 9.4.41 already contains the fix from upstream commit be1eb26670 (July 2017, Simone Bordet), which properly resets _trailers to null in the recycle() method called after each request..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5f9a33-77c3-5b4a-9980-590524eeed67",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax. Version 9.4.41.v20210516 is not vulnerable. Summary: Target repository is Jetty 9.4.41.v20210516, which is outside the affected version range (12.0.0-12.0.31 and 12.1.0-12.0.5) and has a fundamentally different architecture that does not contain the vulnerable code patterns. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c36a9578-04af-56c7-87d6-3832f7d04772",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba9c0fd-01b4-5ee2-9927-d10e40e66e05",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:049a59b3-5e15-5f91-9965-aefd58cffd95",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax. not_affected \u2014 Jetty 9.4.41.v20210516 is not affected by CVE-2026-8384. The target version includes upstream fixes from February 2021 (issue #4275, commits 20ef71fe5d7 and f9b5974dedf) that add ambiguous URI path parameter checking. These fixes prevent exploitation of the semicolon-followed-by-dot-segment pattern described in the CVE by rejecting such URIs with a BadMessageException before they reach security..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cb40ee7-7625-5ecd-a95c-a5314d546596",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh is fixed in version 9.4.41.v20210516-tuxcare.2 of org.eclipse.jetty:jetty-util-ajax."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-util-ajax@9.4.41.v20210516-tuxcare.2"
    }
  ]
}