{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ec032813-c420-5ab8-b623-e33e3cc336a6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "websocket-servlet",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7",
      "version": "9.4.58.v20250814-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0f34e863-56c0-558d-b1c3-e0372bf6cd67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fa031c78-eeeb-5ef6-ad88-f7f813acdb30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-28169 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a7b8b5eb-f5a5-593c-8c0f-06879f962fd2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34428 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7b599432-38a4-55ce-ab8d-b85e38021b0f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36478 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:27d001a0-3d62-5ad3-92fc-942c81da65fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:72bd8b4c-7f1a-5409-9fc3-d502e37a2313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7f0638f7-be18-58f7-980f-37e47483d27c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:74f6bf08-749f-5755-95c7-d175b4f45c5e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5a608fe6-557f-5e21-b608-900c81181a0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:982fe2dc-ea60-5a64-9fa3-f5b7c1a70b3c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6763 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:309b292d-d4b9-530c-9322-1256d42f9f0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8184 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c2e7cbb8-6483-5c60-8324-b74b931cef26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11143 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1385869f-6678-500c-ae39-88acd1c71414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-5115 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d8774d75-413e-5d01-b846-157085468cd6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d0a3c81c-65f3-5dad-bfd9-4882167d3a6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10051 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:430895c4-4e2e-5180-90fb-0377302da470",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1605 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:25515439-3d03-5c9f-ad37-6258c47c6ab3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2332 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8f542627-3311-5033-a503-e165602fb94f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0b9db01f-fc65-56b9-b550-7e2b42c8c8af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-6790 affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8acb617e-630b-511a-aa33-a664ddb71522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet. not_affected \u2014 Jetty 9.4.58.v20250814 is not affected by CVE-2026-8384. The vulnerability exists only in Jetty 12's refactored canonicalPath() implementation that combines path decoding and canonicalization with slash-state tracking. Jetty 9.4 uses a two-stage architecture (decodePath() followed by canonicalPath()) that correctly normalizes paths containing semicolon path parameters before dot-dot segments, p...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bc5eeef7-6c6f-54eb-ba18-9fd3febe3192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.58.v20250814-tuxcare.7 of org.eclipse.jetty.websocket:websocket-servlet."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-servlet@9.4.58.v20250814-tuxcare.7"
    }
  ]
}