{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:aee4d066-12c2-553b-93b9-4d9b31ee5655",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "name": "websocket-jakarta-client",
      "version": "11.0.26-tuxcare.2",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:976d29cc-c4f1-5173-a74e-0e4b37090afd",
      "id": "CVE-2023-36479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48177cac-ad47-573b-8f36-dd133a52a9b4",
      "id": "CVE-2024-22201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5abf15de-f7e3-5b7c-aaaa-16e98e3ae41d",
      "id": "CVE-2024-6762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8d126c9-a212-52d1-999a-239de9ee2307",
      "id": "CVE-2024-6763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8641f0-43b3-57ae-9957-d356b144e6e2",
      "id": "CVE-2024-8184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:110245a0-478a-521d-8acd-d7341298349f",
      "id": "CVE-2025-11143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7108096d-cdfc-5b60-8e75-ffe6944251ad",
      "id": "CVE-2025-5115",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-5115 does not affect version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client. Version 11.0.26 is not vulnerable. Summary: CVE-2025-5115 (MadeYouReset) vulnerability patterns exist in the codebase (HTTP/2 WINDOW_UPDATE with delta==0, window overflow, and DATA frames on half-closed streams all trigger RST_STREAM from server), BUT the mitigation has been applied via commit a05e1d031d0 which implements rate control on server-sent RST_STREAM frames (default 128/second limit), preventing the DoS attack. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c2322f4-5c54-5290-863f-7c4e43d9e85a",
      "id": "CVE-2026-10050",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0fd64f-3847-55fd-bd8b-2b40fa570b55",
      "id": "CVE-2026-10051",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8089f010-ccf9-5502-8b91-b04726f75e81",
      "id": "CVE-2026-1605",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client. Jetty 11.0.26 is outside the affected range (12.0.0\u201312.0.31 and 12.1.0\u201312.1.5). CVE-2026-1605 affects the Jetty 12 lifecycle where releasing the request Inflater depends on a response compression callback. This code path is absent in Jetty 11.0.26, where the gzip input interceptor is destroyed during request recycle regardless of response compression. Therefore, the vulnerable resource retention path does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655fbc22-2ce0-55c3-a710-13613d678f0c",
      "id": "CVE-2026-2332",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5c5b03-0cdb-51f0-93bf-1ab124b97db6",
      "id": "CVE-2026-5795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc11d9d-abee-519b-958c-e1ec4fd6e163",
      "id": "CVE-2026-6790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00055ef5-73f9-5967-9208-53a472d94361",
      "id": "CVE-2026-8384",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client. not_affected \u2014 Jetty 11.0.26 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12 where URIUtil.canonicalPath() integrates semicolon path parameter handling with dot-segment normalization and contains a slash state tracking bug. Jetty 11 uses a different architecture with separate decodePath() and canonicalPath() methods that correctly normalize paths containing semicolons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb6fac5-ecbc-5e1a-82da-cbd7ce6804c3",
      "id": "GHSA-58qw-p7qm-5rvh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 11.0.26-tuxcare.2 of org.eclipse.jetty.websocket:websocket-jakarta-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jakarta-client@11.0.26-tuxcare.2"
    }
  ]
}