{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54a064fa-0eca-5ceb-b123-97d441241380",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "jetty-gcloud-session-manager",
      "purl": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003",
      "type": "library",
      "group": "org.eclipse.jetty.gcloud",
      "bom-ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003",
      "version": "9.4.59.tuxcare0003",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:ff9b1da4-d5d6-5566-864c-221e4d60848c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-27216 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is NOT vulnerable to CVE-2020-27216. The vulnerability was fixed in version 9.4.33.v20201020 (October 2020), and 9.4.59 is well beyond that release.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:3f6967a4-a879-5f00-b5bd-9ab746a635b2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: CVE-2021-28169 has been resolved in this repository. The ConcatServlet contains the necessary protections against double-encoded path attacks targeting WEB-INF and META-INF directories. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:9112a2da-a101-50b8-b79c-7e67b8c399ff",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:f66db8f8-ca8f-58d6-ace6-24dde8c2cc55",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36478 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: The target repository has all security fixes from CVE-2023-36478 already applied. The repository is NOT vulnerable to the integer overflow attack in HTTP/2 HPACK header processing. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:dbfc5d5c-d2a2-5db9-9e59-8044f8060e81",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36479 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: CVE-2023-36479 mitigation has been applied. The CGI servlet has been deprecated and removed from all configurations. While the vulnerable code pattern still exists in the source code (command wrapping logic in CGI.java lines 346-359), the servlet is not configured or exposed in any web.xml files, preventing exploitation. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "requires_configuration"
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:caa650f3-44a6-5b8b-8b90-b948178c20e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:fead2358-541d-59ac-a533-fe6b9eaba730",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: CVE-2023-41900 has been patched in the target repository. The fix (commit 477c7d18b85) is present and correctly implemented. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:a75be79e-12ee-51c1-a67a-6ff52a7a8c40",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-22201 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: The target repository (Jetty version 9.4.59.tuxcare00001) already contains the fix for CVE-2024-22201. The HTTP/2 idle timeout connection leak vulnerability has been patched. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:87f7af5b-cdda-5002-a706-8487f4f02388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:47401d59-6d8f-552f-ba0c-a8e0a227e1a2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:296296d2-95af-52d7-9e18-874a9262aea1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. Version 9.4.59 is not vulnerable. Summary: The target repository already has the fix for CVE-2024-8184 applied. The vulnerable non-atomic check-then-act pattern in getRemote() has been replaced with atomic compute() operations, reference counting has been implemented, and cleanup logic has been added to prevent memory leaks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:e6bb2d3e-b518-5d53-a566-2b47ee9c5e64",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:46714282-7b68-5736-9b8e-7b84ee460ef9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:0c027508-9a6e-5e86-9ab4-1ab467572b99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:dcc6e0e1-1ee7-5a3d-bffc-9f9685417b9a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. not_affected \u2014 Jetty 9.4.59 does not contain the CVE-2026-10051 vulnerability. The target properly resets HTTP request trailers between requests via the HttpChannelOverHttp.recycle() method, preventing cross-request trailer leakage. This defensive pattern has been present since trailers support was first added to Jetty 9.4.x in 2017.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:a592608d-c10f-5fdb-8797-6e73b8346b7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:9c6e83a4-f4ac-56b7-9af3-b7d836ddd2f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:7f886c41-b4ee-51d3-a88c-8d9f1404c3e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:1050799c-4085-5944-b4b5-16a21626a6e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:e83d156a-36c1-5df4-a556-d8ef3a7b9d85",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager. not_affected \u2014 Jetty 9.4.59 is not affected by CVE-2026-8384. The vulnerability requires a combined canonicalPath() method that handles encoding, semicolon stripping, and normalization with state tracking - a method that exists in Jetty 12.x but not in Jetty 9.4.x. The target uses a two-step architecture (decodePath then canonicalPath) that avoids the stale-state bug.",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:10531c89-21ef-502b-b38a-f654239fadef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.59.tuxcare0003 of org.eclipse.jetty.gcloud:jetty-gcloud-session-manager."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.gcloud/jetty-gcloud-session-manager@9.4.59.tuxcare0003"
    }
  ]
}