{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:547e643c-f412-5578-8dbd-036d2cdf87bc",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "jetty",
      "purl": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003",
      "type": "library",
      "group": "org.eclipse.jetty.documentation",
      "bom-ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003",
      "version": "10.0.28.tuxcare0003",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:acecf012-294a-5626-aae9-b69ca5792182",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-27216 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. CVE-2020-27216 (temp directory race condition) is NOT present in the target. The upstream Eclipse/Jetty fix (commit 53e0e0e9b25 from Oct 2020) was already included in Jetty 10.0.28 before TuxCare's base. The target uses secure atomic directory creation via Files.createTempDirectory() (lines 104, 236) instead of the vulnerable File.createTempFile() \u2192 delete() \u2192 mkdirs() race pattern.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:a370c67a-adbf-5652-a0cf-f884d12b5350",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The fix was applied in Jetty version 9.4.41/10.0.3/11.0.3 (May 2021), and the target is running version 10.0.28 (March 2026). The double encoding vulnerability in ConcatServlet has been mitigated. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:47ec0c7e-54f3-5d69-9002-294d9038d0f5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:13e47384-9c5d-5944-9e11-875a8151e12e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36478 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not affected by CVE-2023-36478: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:d21ac224-0487-5bcb-a153-a420523efd33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:cf91a1ae-7f65-5794-a5a5-be988deae0f6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40167 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not vulnerable. Summary: The target repository has the fix for CVE-2023-40167 applied. The Content-Length parsing code in HttpParser.java uses strict digit-only validation that rejects '+' prefix, preventing HTTP request smuggling attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:b83deff4-c047-54c8-89d0-90363e7504ac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not vulnerable. Summary: The target repository (Jetty 10.0.28) is NOT vulnerable to CVE-2023-41900. The security fix has been properly applied. The vulnerable code that only called session.removeAttribute() has been replaced with logoutWithoutRedirect() which properly invokes super.logout() to clear all authentication state. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:0d36f2d8-7272-5e1b-98ba-a3210cf51256",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:9acaa7aa-8b75-592b-a100-72cec952b9a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:23e59a31-ca11-5515-8b9c-009d3165e5e6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:70b975fc-f44e-5ebd-95ec-8dbe18ee2b76",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-8184. The security fix has already been applied to ThreadLimitHandler.java, implementing atomic operations with reference counting to prevent memory exhaustion. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:4e009b8d-fa64-5962-b1b8-1513eceb578a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:53fb4fe1-0053-5ab4-bc2e-1fdbc8b537c1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-5115 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:1857875d-58fe-5b3a-b921-5f38fa5cb1de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:fcfd1ade-58d2-5c10-90fc-ae254e4f7b1e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:0788c8a2-34f0-51e1-8cdd-b5d65685a2b2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. Version 10.0.28 is not vulnerable. Summary: Target repository runs Jetty 10.0.28 which uses a fundamentally different architecture than the vulnerable Jetty 12.x versions. The cleanup mechanism for decompression resources is tied to the request lifecycle (Request.recycle) rather than the response lifecycle, preventing the resource leak described in CVE-2026-1605. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:bd82426a-a9d5-5d00-b244-61d4e9ac03e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2332 is fixed in version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:bcc8757b-e0ff-5b29-87ec-c8e3d545c828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:e30841af-ca83-53fb-a610-32d480cdf999",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:801be11c-4b95-5f9c-be45-c367970c7f34",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty. not_affected \u2014 Jetty 10.0.28 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.x's unified canonicalPath() method which attempts to handle percent-decoding, semicolon parameter stripping, and dot-segment normalization in a single pass with slash-state tracking. Jetty 10.0.28 uses a fundamentally different two-step architecture where decodePath() and canonicalPath() are separate methods th...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:8ba12a8b-7188-523f-9c16-e3f3ba4f56d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.28.tuxcare0003 of org.eclipse.jetty.documentation:jetty."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.documentation/jetty@10.0.28.tuxcare0003"
    }
  ]
}