{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5122d6d4-fdf1-5d23-ac38-ff77f644bf95",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "websocket-jetty-common",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003",
      "version": "10.0.29.tuxcare0003",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:54d2a38f-774b-5d81-a82e-6ffab9794550",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-27216 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.29 is not vulnerable. Summary: CVE-2020-27216 has been fixed in this repository. The target is running Jetty 10.0.29, which is well after the affected version range (10.0.0.alpha1 through 10.0.0.beta2). The vulnerable temporary directory creation pattern using File.createTempFile() followed by delete() and mkdirs() has been replaced with the secure Files.createTempDirectory() method, which provides atomic creation with restrictive permissions (0700 on Unix). [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:770c87df-5e06-5c5a-a84a-4988c1c5bfe5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.28 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The fix was applied in Jetty version 9.4.41/10.0.3/11.0.3 (May 2021), and the target is running version 10.0.28 (March 2026). The double encoding vulnerability in ConcatServlet has been mitigated. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:eec7e486-6b95-51a9-a082-65f8bfcb2227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:4ffde61c-eedb-5e40-ab57-b7f60ad21967",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36478 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.29 is not affected by CVE-2023-36478: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:897243fd-8cff-5376-88c5-0d1996d961dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:ed822871-a9f8-5c0a-8db1-a38ac471548a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40167 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.28 is not vulnerable. Summary: The target repository has the fix for CVE-2023-40167 applied. The Content-Length parsing code in HttpParser.java uses strict digit-only validation that rejects '+' prefix, preventing HTTP request smuggling attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:716beb09-d7a2-585a-ad9a-1709118fc737",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41900 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.28 is not vulnerable. Summary: The target repository (Jetty 10.0.28) is NOT vulnerable to CVE-2023-41900. The security fix has been properly applied. The vulnerable code that only called session.removeAttribute() has been replaced with logoutWithoutRedirect() which properly invokes super.logout() to clear all authentication state. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:0b596954-6059-5c9b-9c9b-3b3b3f64ce7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:5d53b45f-c5b3-573b-ba10-7355e1cbe366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:38effff7-7d6a-5c12-9f06-d5c56f8125e4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:b713a727-d882-5429-a2cf-4ae313c15a5a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.28 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2024-8184. The security fix has already been applied to ThreadLimitHandler.java, implementing atomic operations with reference counting to prevent memory exhaustion. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:88a6b31c-02f8-567f-8384-5e49284f0898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:4331c658-7af9-542d-9644-12c032dfbb61",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-5115 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:2eea96fe-0041-54aa-9afb-79f4d187a767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:fb7abd76-3e9f-561c-b27a-e0429f6f665d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. not_affected \u2014 Jetty 10.0.29 is not affected by CVE-2026-10051. The vulnerability concerns connection-scoped trailer state in Jetty 12+ that persists across requests, but Jetty 10.0.29 uses a different architecture where trailers are channel-scoped and properly reset between requests via the channel recycle mechanism.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:3803b808-935d-5650-9f88-bc94770e6b32",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. Version 10.0.28 is not vulnerable. Summary: Target repository runs Jetty 10.0.28 which uses a fundamentally different architecture than the vulnerable Jetty 12.x versions. The cleanup mechanism for decompression resources is tied to the request lifecycle (Request.recycle) rather than the response lifecycle, preventing the resource leak described in CVE-2026-1605. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:96367f0c-1a29-55a6-9a2c-10fe68d6cdfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2332 is fixed in version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:fa846d87-a78b-5ef3-9edb-d642150fa9f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:f19628c3-9a66-5586-a260-c6cd3f361988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:63facc59-a18c-5bee-ae80-b422524a6bf8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common. not_affected \u2014 Jetty 10.0.29 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath implementation where a stale variable prevents dot-segment normalization after semicolon path parameters. Jetty 10 uses a different two-step architecture (decodePath then canonicalPath) that correctly normalizes paths containing ';/../' patterns.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
        }
      ],
      "bom-ref": "urn:uuid:1f014d80-6755-5260-98a2-72ed820e92fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 10.0.29.tuxcare0003 of org.eclipse.jetty.websocket:websocket-jetty-common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-jetty-common@10.0.29.tuxcare0003"
    }
  ]
}