{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c514d2ac-5fe0-5dae-b9bf-360bd9b4a968",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "websocket-server",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7",
      "version": "9.4.58.v20250814-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:281c46a3-e478-5326-8e33-37543d232d4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:16670ede-5e1f-5367-b958-bf384af79323",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:733fd37c-35e9-5b34-bd64-9c47e0c9c92b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:71f78ca2-81d4-502a-81dd-470cea3692ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2a50a21c-781c-5f98-b94f-b53547074904",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5e8237b4-a0b0-5559-a928-dc131a00186f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8e4427e3-2036-53d2-b073-94335b054ba6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1595de17-0402-5662-be3b-f2689d590349",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4eb52a71-0cd0-5847-8650-5038b390cc65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1dcfccb0-1b3f-534c-a23a-1ae95e8b67a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:521a4cb1-6626-5ba2-9e06-70cc9dfdf817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:918b388b-e1bd-5921-9c04-f5de9cbebee0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:54fe4357-3f76-551a-9ab2-59109849f33d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:469e4436-18c5-584d-9f24-9a143f437d13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1a70c22e-ccc7-5dd3-b5d7-7bebe9dbbe77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:57256bae-e7c3-5b1d-9742-225dd6aac199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f5ef0d1b-7b9c-5742-ae3d-f7cfa250bfbe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:69a4f3a2-413a-5a91-867a-0887a18bca86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4f5d694e-c953-5dd0-945e-9c2ae66bf2f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0c6d2857-c9fb-5066-ad23-6bc249977be1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:824ff05f-ccb4-50e3-89cb-8b1f98dae4d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-server@9.4.58.v20250814-tuxcare.7"
    }
  ]
}