{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dbe38101-2f16-52b8-98df-fd35ccf65924",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "jetty-memcached-sessions",
      "purl": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7",
      "type": "library",
      "group": "org.eclipse.jetty.memcached",
      "bom-ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7",
      "version": "9.4.58.v20250814-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6cf08d1d-165f-503e-82af-dbbc77abf674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:96bbc04e-d63c-5382-9e97-5b58c7cda231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7100ebb8-5ede-55e2-ba5d-d6bd63248934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ea785000-ef1c-56c8-a7df-c37f62001e24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ae7dbb3d-a25d-5a25-97ab-a2a8778f3224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6e07c8bc-5aa7-599b-891b-542165df300b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:28f5526f-12b7-52a3-a6f7-bd1332b5410a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:318535d9-cdff-5382-8856-7572a01bde78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3de97d0f-baad-5cca-8db9-5a04c2e9cbae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:89ec864b-d3cc-5563-a781-7b0f9809fb3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ba26d982-5d72-57df-8d61-22a0ca975dbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3fa45f5e-dd9c-5c05-824d-3d24b994089f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7f090c14-8590-555f-b912-ac93d269d5ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:06c2fd3b-a5bb-5b36-8c63-353768a5b821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e22c3ec4-7748-5455-bd2f-7c379b54ec7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:59915497-1b3e-53a9-bf04-a2dafed31aba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:438e864e-5821-5068-918b-1702b3b99d10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:01f32b9c-5416-5151-a6cb-0a4b72d8165d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e2809157-acc2-59e3-8ada-4960cd4ca373",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6d15e4a0-8601-54cb-a604-a24f6c614440",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cf79e396-0457-5e9d-9177-8276690d965e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.memcached:jetty-memcached-sessions."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.memcached/jetty-memcached-sessions@9.4.58.v20250814-tuxcare.7"
    }
  ]
}