{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4bf8bf88-596c-5b56-8fd5-1316511a2e42",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "jetty-websocket",
      "version": "8.2.0.v20160908-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e732c0b4-7411-5e4d-8f8e-30a5e4d393fe",
      "id": "CVE-2015-2080",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2015-2080 is a false positive for org.eclipse.jetty:jetty-websocket 8.2.0.v20160908-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f53fd8-8749-53f0-9729-9ff9bb95c76e",
      "id": "CVE-2017-7656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7656 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed41e9a8-7e06-5512-9fa1-cdfdd8d84bf1",
      "id": "CVE-2017-7657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7657 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c90bcb68-68be-56d5-8af8-0a899b55f143",
      "id": "CVE-2017-7658",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7658 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b680e3e-7a77-55f9-bba2-10dcf3d99460",
      "id": "CVE-2017-9735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-9735 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9efa675-0427-5701-ad1d-612a8012b8f5",
      "id": "CVE-2018-12536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12536 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b93c9c05-d784-5946-b5c2-dbd98e8b5067",
      "id": "CVE-2018-12538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12538 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c643322-7940-5711-800d-0b07e96a5d8c",
      "id": "CVE-2018-12545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-12545 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Target version 8.2.0.v20160908 does not contain HTTP/2 protocol support, which was introduced in Jetty 9.3.0. CVE-2018-12545 affects HTTP/2 SETTINGS frame processing in versions 9.3.x and 9.4.x. The target only has SPDY support (jetty-spdy module), but the vulnerability is HTTP/2-specific. All security patches for this CVE modified jetty-http2 code exclusively. SPDY was deprecated and removed from Jetty in early 2018, before the CVE-2018-12545 patches were applied in 2019, confirming the vulnerability is HTTP/2-only."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52693f1-de5c-5fae-bb47-430af04bed3d",
      "id": "CVE-2019-10241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10241 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a19de0e-4300-52b7-8a08-d0429fc9ae42",
      "id": "CVE-2019-10246",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-10246 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. not_affected \u2014 Version 8.2.0.v20160908 is NOT affected by CVE-2019-10246. The vulnerable code pattern (iterating over Resource[] items and calling getName() which returns absolute paths) does not exist in this version. Version 8.2.0 uses a different architecture where directory listings iterate over String[] from File.list() which returns only filenames, never exposing full filesystem paths. The vulnerability..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4092f4d5-4d6c-53cd-8604-cc9ec9b0c18c",
      "id": "CVE-2019-10247",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10247 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:854ed761-bf2d-5410-b054-dcb33ac18af3",
      "id": "CVE-2019-17638",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-17638 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. CVE-2019-17638 is a double release of the pooled response-header ByteBuffer in Jetty's HTTP/1 server connection. It requires the code path introduced in Jetty 9.4.27.v20200227, where org.eclipse.jetty.server.HttpConnection's SendCallback reacts to the generator's HEADER_OVERFLOW result for an over-long response header by releasing the header buffer back to the ByteBufferPool and then throwing to produce the HTTP 431, leaving the field set so the connection's cleanup releases the same buffer again. Two threads then acquire one buffer from the pool and a client receives another client's response data. Upstream removed the second release in 9.4.30.v20200611 by checking the buffer capacity before releasing and by nulling the reference in a dedicated release helper. Jetty 8.2.0.v20160908 predates that architecture. Its jetty-server module contains no HttpConnection class, no SendCallback, no HEADER_OVERFLOW generator state and no org.eclipse.jetty.io.ByteBufferPool; responses are generated by org.eclipse.jetty.http.HttpGenerator/AbstractGenerator over the org.eclipse.jetty.io.Buffers pool, and org.eclipse.jetty.http.HttpStatus does not define status 431 at all. On this version an over-long response header surfaces as an ArrayIndexOutOfBoundsException that HttpGenerator.completeHeader rethrows as a RuntimeException; AbstractHttpConnection.commitResponse and completeResponse catch it, call _generator.reset() - which merely clears the existing header buffer and keeps it - and write a 500 response into that same buffer. No buffer is returned to the pool anywhere on that path. The pool is touched only by AbstractGenerator.returnBuffers(), which returns the header and content buffers under a length()==0 guard and nulls each field in the same block, so a buffer that has been returned cannot be returned a second time. The double release the vulnerability depends on has no counterpart in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f30e42-e987-5eea-88b6-88ab489c9fb3",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-27216 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4daa3e42-b7b7-5322-ac07-b8c3fada8891",
      "id": "CVE-2020-27218",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-27218 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. not_affected \u2014 Jetty 8.2.0.v20160908 does not contain GZIP request body inflation functionality. CVE-2020-27218 affects Jetty versions with GzipHandler request inflation capability, which was first implemented in March 2019 (commit c1f6f6b6082) for Jetty 9.4.x, 2.5 years after this version was released. The target version only supports GZIP response compression, not request decompression, making the vulnerabi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e53e29be-92f0-589a-a4a3-f81a1780bc95",
      "id": "CVE-2021-28165",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-28165 is a false positive for org.eclipse.jetty:jetty-websocket 8.2.0.v20160908-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e30b7786-69d0-5b3c-a2cc-e4da52b8da99",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-28169 is a false positive for org.eclipse.jetty:jetty-websocket 8.2.0.v20160908-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cbf27d7-1dfe-5585-9a44-53d2167aa7a3",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34428 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22cb83d-c404-5263-8067-8b01fd027c73",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2596e969-9a6f-544b-899f-2258f21a9b98",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-2048 is a false positive for org.eclipse.jetty:jetty-websocket 8.2.0.v20160908-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a663c5c8-fea5-5d40-8571-f185a0b70e6c",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26048 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a396c70-fa91-5a3d-996e-c5a1e05c66ed",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26049 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85b5030-7048-524a-a10d-6cdd3b02397a",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbf348ec-44c7-5c3d-9604-7d1e315729fa",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40167 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Version 8.2.0.v20160908 is not vulnerable. Summary: The target repository (Jetty 8.2.0.v20160908) is NOT vulnerable to CVE-2023-40167. Unlike newer Jetty versions (9.x+) that use Long.parseLong() for Content-Length parsing, this version uses BufferUtil.toLong() which correctly rejects the '+' prefix as per RFC 9110. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d0d63e4-911d-5053-8833-061208608adb",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-44487 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. The version is not vulnerable. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4390d180-aa16-5696-8d29-0be91dc9048a",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-13009 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Target version 8.2.0.v20160908 is NOT AFFECTED by CVE-2024-13009. The vulnerability requires the Interceptor-based gzip request body decompression architecture and Content buffer lifecycle management introduced in Jetty 9.4.x. Version 8.2.0 uses a fundamentally different architecture: HttpInput is a simple 75-line class with no _content field, no Interceptor mechanism, and no support for gzip-compressed request bodies. Exhaustive searches confirmed the INPUT (gzip-compressed HTTP request bodies) is not processed anywhere in version 8.2.0. The vulnerable pattern cannot exist in this architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84490526-dc2d-5473-a846-e87301e7237b",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6762 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Version 8.2.0.v20160908 is not vulnerable. Summary: CVE-2024-6762 does not affect the target repository. The vulnerable classes PushCacheFilter and PushSessionCacheFilter are not present in Jetty 8.2.0.v20160908. These HTTP/2 Server Push filters were introduced in later versions (Jetty 9.x+) and do not exist in Jetty 8.x. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e395aa-ab22-5008-ab33-b411069f7236",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802f322b-a602-505f-a693-1ac4e7a1b6d2",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Version 8.2.0.v20160908 is not vulnerable. Summary: The target repository (Jetty 8.2.0.v20160908) does not contain the ThreadLimitHandler class that is affected by CVE-2024-8184. This vulnerability is specific to ThreadLimitHandler.getRemote() which was introduced in later versions of Jetty (likely 9.4.x or later). Since the vulnerable component does not exist in this older version, the target is not affected by this CVE. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce36ab2d-e6e2-57c3-9b03-7e27832cc2f4",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e3ee00-eb1c-5678-a038-e2dd3ab2531a",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cef4d032-1b6e-5674-959c-8fbfbba17448",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. not_affected \u2014 Jetty 8.2.0 does not support HTTP trailers at all, so the trailer cross-request leakage vulnerability cannot manifest. The HttpParser immediately completes message processing upon encountering the final chunk without parsing the trailer-part section, and no trailer-related fields, methods, or APIs exist in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87eabbec-2ccc-51b0-9577-6875df311b58",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. Version 8.2.0.v20160908 is not vulnerable. Summary: Target repository is Jetty 8.2.0.v20160908, which does not have the HTTP request decompression feature that contains CVE-2026-1605. The vulnerability only affects Jetty 12.0.0-12.0.31 and 12.1.0-12.1.5. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae1fdeb-238a-57e4-af03-61ee80e1436f",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7087ea91-b9b1-516e-bce1-78bc780dd25a",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edcde701-e179-50ef-8b5a-7feffa9c1114",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-6790 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. not_affected \u2014 Jetty 8.2.0.v20160908 does not implement HTTP/2 or HTTP/3, which are required to receive the CVE's attack INPUT (HTTP/2 or HTTP/3 request with mismatched :authority and Host headers). The target only supports HTTP/1.1 and SPDY (v2 and v3). SPDY uses :host pseudo-header, not :authority, and is architecturally different from HTTP/2. The vulnerability cannot manifest in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be622384-e4f0-58ae-b48e-8fb725c95a0b",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket. not_affected \u2014 Jetty 8.2.0.v20160908 is not affected by CVE-2026-8384. The vulnerability requires a specific architectural pattern present in Jetty 12.x where path parameter stripping and path normalization occur in a single forward-scanning pass within canonicalPath(). Jetty 8.2.0 uses a fundamentally different two-stage architecture: HttpURI parsing strips path parameters by setting the _param boundary (eve..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789ddc0e-ec63-5fe8-b3c4-d05ca3267498",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 8.2.0.v20160908-tuxcare.2 of org.eclipse.jetty:jetty-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/jetty-websocket@8.2.0.v20160908-tuxcare.2"
    }
  ]
}