{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b127503d-89b3-53d6-ab65-8707905d8ba2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1",
      "type": "library",
      "group": "org.eclipse.jetty",
      "name": "test-jetty-servlet",
      "version": "7.6.0.v20120127-tuxcare.1",
      "purl": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:df6a6394-a34e-5795-abe2-02f47d91ab88",
      "id": "CVE-2011-4461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2011-4461 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1051f41b-04cc-5acf-90b1-d31fc237dd5c",
      "id": "CVE-2015-2080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-2080 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f62a96da-8d6a-5326-9b56-d573ea204de9",
      "id": "CVE-2017-7656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7656 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:405d2aae-7a52-5532-a2d0-991a21166ea1",
      "id": "CVE-2017-7657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-7657 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67acd22-1ed1-5db3-a439-37ed88aa361e",
      "id": "CVE-2017-7658",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7658 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b41090-4098-57a3-a874-d7a4072f082b",
      "id": "CVE-2017-9735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-9735 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6cb0cb3-1d64-55ae-918c-0e1adbcd1032",
      "id": "CVE-2018-12536",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-12536 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. not_affected \u2014 CVE-2018-12536 is specific to java.nio.file.InvalidPathException revealing full filesystem paths in Jetty 9.x when malformed paths trigger exceptions. The target version (Jetty 7.6.0.v20120127) targets Java 5 and uses the java.io.File API exclusively, not java.nio.file.Path. InvalidPathException was introduced in Java 7 NIO.2 and does not exist in Java 5. The vulnerable code pattern (PathResour..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b51fcc-5872-5443-ac4c-b64889ef4c0c",
      "id": "CVE-2018-12538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-12538 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8bdf85a-e071-5ab0-9682-7cd34cbb1720",
      "id": "CVE-2018-12545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-12545 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Jetty 7.6.0.v20120127 is not affected by CVE-2018-12545. This version predates HTTP/2 standardization by over 3 years (released January 2012, HTTP/2 standardized May 2015) and contains no HTTP/2 protocol implementation. The vulnerability requires HTTP/2 SETTINGS frame processing capability, which does not exist in this version. The CVE explicitly targets versions 9.3.x and 9.4.x where HTTP/2 support was introduced. Comprehensive code search found no HTTP/2-related modules, classes, or frame handling logic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:145feb4d-b27b-582e-b555-93bb4f9e228c",
      "id": "CVE-2019-10241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10241 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528abe86-0463-5582-92f2-12a6d9fe10fe",
      "id": "CVE-2019-10246",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-10246 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f72b0362-c66a-56f3-a05a-c3a5a289b50d",
      "id": "CVE-2019-10247",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-10247 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ada3a39f-da29-528f-8431-e9f6abd841e8",
      "id": "CVE-2019-17638",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-17638 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is NOT AFFECTED by CVE-2019-17638. The target uses a fundamentally different architecture (Buffer/Buffers interface from 2012) with built-in atomic return-and-null buffer management, preventing the double-release vulnerability that was introduced in version 9.4.27-9.4.29 (2020) when the codebase was refactored to use ByteBuffer/ByteBufferPool. The dangerous operation (buffer pool double-release leading to cross-client data exposure) cannot be reached in version 7.6.0's architecture. The CVE-affected versions (9.4.27.v20200227 to 9.4.29.v20200521) are from 8 years after this target version was released."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e9d0e1d-b9ad-5a01-b80a-db2eb239dc2c",
      "id": "CVE-2020-27216",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-27216 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not affected by CVE-2020-27216: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93968f66-b269-5041-a570-bbf660ae19aa",
      "id": "CVE-2020-27218",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27218 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ec7b490-179d-5062-be47-db85049f9c89",
      "id": "CVE-2021-28165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-28165 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a6efba-06c1-51fc-99ca-0ac9982bdbba",
      "id": "CVE-2021-28169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:325e711c-377a-580d-8875-891e28208b46",
      "id": "CVE-2021-34428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not vulnerable. Summary: The target repository (Jetty 7.6.0.v20120127) is NOT vulnerable to CVE-2021-34428. While the CVE affects versions <= 9.4.40, <= 10.0.2, <= 11.0.2, the vulnerability is specific to the code architecture introduced in Jetty 9.x onwards. Version 7.6.0 uses the older AbstractSessionManager architecture where invalidateAll() is called BEFORE sessionDestroyed() listeners, ensuring the session ID is properly invalidated even when l [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f89b495-43ae-5a72-bf78-3ee01c0c2f12",
      "id": "CVE-2022-2047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2047 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6003bbb-15dc-5a40-bc9d-f67c7a00accf",
      "id": "CVE-2022-2048",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-2048 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Jetty 7.6.0.v20120127 does not have HTTP/2 protocol support. CVE-2022-2048 affects the HTTP/2 server implementation in HttpChannelOverHTTP2.java (part of the jetty-http2 module), which does not exist in this version. HTTP/2 support was added to Jetty in version 9.3.x (2015), but this version is from January 2012, predating HTTP/2 by approximately 3 years. The target cannot receive the Brief's INPUT (invalid HTTP/2 requests) because it lacks any HTTP/2 protocol implementation."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870c1026-dd43-5fcf-9b36-c1c2a7dea2a3",
      "id": "CVE-2023-26048",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26048 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3b78532-1689-5124-bc15-249a85a9e12a",
      "id": "CVE-2023-26049",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-26049 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0da3902-b95b-5215-aed1-dcc978260faf",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-36479 is fixed in version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e9d041b-44d0-5822-8dae-f83160d14948",
      "id": "CVE-2023-40167",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40167 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not vulnerable. Summary: The target repository (Jetty 7.6.0.v20120127) is NOT vulnerable to CVE-2023-40167. This version uses BufferUtil.toLong() which rejects '+' prefix in Content-Length values, while the CVE affects Jetty 9.4.x+ versions that use Long.parseLong() which accepts '+' prefix. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3c33f4-d321-516f-a28d-d73f566cd7bc",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435be09b-ae61-5649-b736-33239e1bc7c7",
      "id": "CVE-2024-13009",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-13009 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. CVE-2024-13009 does not affect Jetty version 7.6.0.v20120127. The vulnerability requires gzip request body decompression with a content interceptor system and buffer queue management (the `_content` field in HttpInput). Version 7.6.0 predates this architecture entirely: its HttpInput (73 lines) is a simple wrapper around HttpParser.blockForContent() with no content queue, no interceptor mechanism, and no server-side request body gzip decompression capability. The vulnerable code pattern was introduced in later 9.4.x versions."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66dc5cc4-4fd8-5e10-8c1e-cda08b3237cf",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb1b72ca-8096-58a3-9576-0f3ea07c087c",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00d6a19-f04a-528a-a68a-95408e647feb",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not vulnerable. Summary: Target repository is NOT vulnerable to CVE-2024-8184. The ThreadLimitHandler class, which contains the vulnerability, does not exist in this version of Jetty (7.6.0.v20120127 from January 2012). ThreadLimitHandler was introduced in later versions of Jetty. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e74d16-13c4-584d-a8f0-6216bba414e2",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-11143 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not vulnerable. Summary: Analysis cannot proceed: both patch content and CVE description are empty [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b904b6d3-fb52-5fca-9ea5-269c9107a65a",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:048123ae-cb60-5526-bd6f-702a0e9090b4",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. not_affected \u2014 Jetty 7.6.0.v20120127 does not implement HTTP trailer parsing. The CVE-2026-10051 vulnerability concerns a connection-scoped `_trailers` field that leaks between requests on keep-alive connections, but this version predates trailer support by 5 years. Trailer parsing was first added in Jetty 9.4.2 (January 2017); this version is from January 2012."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc321e20-7812-5d07-8fd3-fc03644bdc5c",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. Version 7.6.0.v20120127 is not vulnerable. Summary: Target repository (Jetty 7.6.0.v20120127) is not vulnerable to CVE-2026-1605. The vulnerability requires HTTP request decompression functionality that does not exist in Jetty 7.x. The affected code paths (GzipRequest, GzipDecoderSource, InflaterPool) are only present in Jetty 12.x architecture. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab375a09-d18f-5070-adb5-c05b6804a9ba",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a603bea-7510-5102-9ef8-a875fe4b2582",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5795 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87b08db5-03f0-5ca0-b573-dd1be546fd6b",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:933cb1be-14dc-5e9d-b243-0a2f5a510807",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet. not_affected \u2014 Jetty 7.6.0.v20120127 is not affected by CVE-2026-8384. The vulnerability describes a bug in Jetty 12.1.8's URIUtil.canonicalPath() method where semicolon path parameter handling fails to update the 'slash' variable, causing dot-dot segments to remain unnormalized. However, Jetty 7.6.0 uses a fundamentally different architecture: semicolon path parameters are stripped BEFORE path normalization ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b3d53e7-b284-5ef0-822f-d7aa179e99f0",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 7.6.0.v20120127-tuxcare.1 of org.eclipse.jetty:test-jetty-servlet."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty/test-jetty-servlet@7.6.0.v20120127-tuxcare.1"
    }
  ]
}