{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54f5c518-0102-56ba-a7e8-ff2f823024d6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "websocket-core-client",
      "purl": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001",
      "type": "library",
      "group": "org.eclipse.jetty.websocket",
      "bom-ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001",
      "version": "11.0.31.tuxcare0001",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:0f90ea87-6705-5e71-8044-7ad6c5092333",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36479 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. Version 11.0.30 is not affected by CVE-2023-36479: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:967c2cf0-67a3-5bd9-ae47-202f1f259cca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:ce4904fe-c961-5af9-a73d-c92db64c0a8e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6762 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. All 2 patch commits already exist in target branch"
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:9013a207-ef57-5ee9-8130-0cdfa6802c27",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:368018c0-1710-53d7-8ac8-775025f57bc2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. Version 11.0.28 is not vulnerable. Summary: The target repository already has the security fix for CVE-2024-8184 applied. The code uses atomic compute() operations with reference counting and proper cleanup mechanisms to prevent memory exhaustion. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:aef1a8c2-4157-5dc5-9994-9c73142eae7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:3fa0706c-fb05-5f0a-98f4-abb2c3be10eb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-5115 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:ecc832ab-f98e-53bd-af4f-829b89f151ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-10050 is fixed in version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:65daca4a-1a8f-5034-9b92-37ac4a350a1e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. Jetty 11.0.30 is outside the affected range (12.0.0\u201312.0.35 and 12.1.0\u201312.1.9). CVE-2026-10051 affects the Jetty 12 lifecycle where connection-scoped trailer state can survive parser reuse. This code path is absent in Jetty 11.0.30, where the HTTP channel clears its trailer state during request recycle before the parser is reused. Therefore, trailer state cannot leak between requests in this version."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:a95484fc-fd57-5041-874c-62c6a438df4d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. Version 11.0.28 is not vulnerable. Summary: Target repository is NOT vulnerable to CVE-2026-1605. The vulnerability affects Jetty 12.x (versions 12.0.0-12.0.31 and 12.1.0-12.0.5), while the target is running Jetty 11.0.28.tuxcare0001, which uses a different architecture for request decompression that does not exhibit this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:fe5587b9-7d3b-599f-a067-6d31a7b9a9ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2332 is fixed in version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:f9ebd1e5-96f7-566e-afbf-cc15b5d16f58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:c3775406-7233-5026-9406-a0483c762e79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:776d19bb-7adc-59ce-b888-c591c0cd853c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client. not_affected \u2014 Jetty 11.0.30.tuxcare0002 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12's unified canonicalPath() method where slash state tracking gets corrupted when processing semicolon path parameters. Jetty 11 uses a different two-stage architecture that separates semicolon stripping (decodePath) from dot normalization (canonicalPath), preventing the vulnerable pattern from manife...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:c4596dcf-daa9-5e32-b27f-1d6b3755da41",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 11.0.31.tuxcare0001 of org.eclipse.jetty.websocket:websocket-core-client."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.websocket/websocket-core-client@11.0.31.tuxcare0001"
    }
  ]
}