{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:af5cc07d-4feb-5477-acb5-2ac9874b9111",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "gcloud-parent",
      "purl": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003",
      "type": "library",
      "group": "org.eclipse.jetty.gcloud",
      "bom-ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003",
      "version": "9.4.61.tuxcare0003",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:859c650a-abb9-5351-b122-0193366d6cf2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:33354166-52e4-5a7b-b63b-7247da3459f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The ConcatServlet now properly validates paths before dispatching, preventing double-encoded path traversal attacks to access WEB-INF/META-INF protected resources. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:1bdc0d84-cda9-5016-9b83-34811ac1e689",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. Version 9.4.61 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:6ef397d4-568e-542f-9070-8d3b749aad69",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36478 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. Version 9.4.59 is not vulnerable. Summary: The target repository has all security fixes from CVE-2023-36478 already applied. The repository is NOT vulnerable to the integer overflow attack in HTTP/2 HPACK header processing. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:4824f39c-7af8-5abc-919e-be45a2357e6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:bea77851-84b0-517c-a665-f9dc051dcf7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:d81b09e0-4038-5b41-b826-8cf6d65b25a9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:2143ccc9-a158-5808-adf4-034065718db1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:8ef4e470-6bf7-5113-8b75-41224d2b8c03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:1c4b6245-e72e-58a5-a7c9-a9f41c4f9bfc",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:42f301c4-f454-5436-ab10-e4292299c886",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. Version 9.4.60 is not vulnerable. Summary: The target repository (Jetty 9.4.60.tuxcare0001) already has the CVE-2024-8184 fix applied. The ThreadLimitHandler uses atomic reference counting with ConcurrentHashMap.compute() methods instead of the vulnerable get+putIfAbsent pattern. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:e35fe8c4-2e22-5e57-a23f-744c2c9aa283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:dbf66c1e-ebfb-50e3-a5dc-ebb8353ba6ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:a83b4a55-fc0c-5f25-be89-d874363e68a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:171a45da-aa16-5095-b82f-d915678b48ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:824c57d7-0a21-56a3-bc20-4bf644260253",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2026-1605 does not apply to Jetty 9.4.60. The vulnerability is specific to Jetty 12.x architecture which uses different classes and lifecycle management. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:b7917a4c-96db-5730-9ca3-e754c4483365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2332 is fixed in version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:2732973e-53d4-5a8c-bd62-04de4a7a197f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:65b73ad0-e81e-525a-bd24-4c71a7ab7a14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:c672f9b0-8f70-57c1-b819-5d725fb946bd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent. not_affected \u2014 Jetty 9.4.61 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.1.8's refactored canonicalPath() function that handles both semicolon stripping and dot normalization in one pass. Jetty 9.4.61 uses a different architecture with two separate functions (decodePath then canonicalPath), preventing the vulnerable code pattern from existing. Paths like /path;/../target are correctl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:acfe1ff5-efe3-5eb4-a38e-5ce7e9b51447",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.61.tuxcare0003 of org.eclipse.jetty.gcloud:gcloud-parent."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.gcloud/gcloud-parent@9.4.61.tuxcare0003"
    }
  ]
}