{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b4e74e4-4e13-5947-b066-a107aed278ff",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "memcached-parent",
      "purl": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001",
      "type": "library",
      "group": "org.eclipse.jetty.memcached",
      "bom-ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001",
      "version": "9.4.65.tuxcare0001",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2020-27216",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:69c50730-4de7-5e0d-9543-05f3ff590d42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-27216 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2021-28169",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:3152afb0-d644-55f4-81e1-300a83e5e59f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-28169 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2021-28169 has been patched in the target repository. The ConcatServlet now properly validates paths before dispatching, preventing double-encoded path traversal attacks to access WEB-INF/META-INF protected resources. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2021-34428",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:52c634ff-a4bf-52eb-b38f-2d8cc7f4b4b4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-34428 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. Version 9.4.62 is not affected by CVE-2021-34428: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      }
    },
    {
      "id": "CVE-2023-36478",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:c2be5519-bcfb-5b00-930b-ab5f5b7a93ad",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36478 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. Version 9.4.59 is not vulnerable. Summary: The target repository has all security fixes from CVE-2023-36478 already applied. The repository is NOT vulnerable to the integer overflow attack in HTTP/2 HPACK header processing. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2023-36479",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:ad0ebff6-4518-5310-b046-51fe4810df60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36479 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2023-40167",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:bd43e488-5bac-52c4-9206-1f4354706bf7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40167 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2023-41900",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:cec024a1-2eac-5a84-bc70-d68ac98f65d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41900 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2024-22201",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:5e247adc-0bd0-5712-a835-c8d33bb40b03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22201 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2024-6762",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:5e549d45-13ec-5c5a-820a-a9885c4194e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6762 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2024-6763",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:9e983f97-0d50-5134-8bbb-1ad1771f4b0a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-6763 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. fix for CVE for this version has been already backported by the original developers, so this brunch is not vulnerable",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2024-8184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:9ba3619a-b718-5d30-a5ec-9ea0cd1ba77e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-8184 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. Version 9.4.60 is not vulnerable. Summary: The target repository (Jetty 9.4.60.tuxcare0001) already has the CVE-2024-8184 fix applied. The ThreadLimitHandler uses atomic reference counting with ConcurrentHashMap.compute() methods instead of the vulnerable get+putIfAbsent pattern. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-11143",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:c1895d3a-fa9c-58bf-9d5f-ba524af44659",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11143 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2025-5115",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:414258da-4415-5837-abb0-2b900ca8697c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-5115 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-10050",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:4c528527-a833-50a7-ac53-569a82dc1592",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10050 affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-10051",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:caa0cf95-dda5-524d-96c4-76bf3ef28ee9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-10051 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. not_affected \u2014 Version 9.4.x uses a different architecture than the affected 11.x/12.x versions. The vulnerability requires a connection-scoped HttpConnection._trailers field that is never cleared between requests. Version 9.4.x instead uses HttpChannel-scoped _trailers that IS properly cleared in HttpChannel.recycle(), preventing cross-request trailer leakage.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-12611",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:e4331122-ba66-5ee9-b58b-604b8984ad51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-12611 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-1605",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:464efc9d-24e5-5dac-b522-4bdba0358b61",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1605 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. Version 9.4.60 is not vulnerable. Summary: CVE-2026-1605 does not apply to Jetty 9.4.60. The vulnerability is specific to Jetty 12.x architecture which uses different classes and lifecycle management. [terminalized not_affected from patch_application_manual/not_vulnerable]",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-18659",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:b39b4162-b02b-5342-8b2b-3f85045d1ae3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-18659 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-18660",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:aff5626f-6ea7-5b6a-b911-1ed6f526b68b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-18660 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-18661",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:bd29d17a-6647-562e-9828-ea695bdbf6ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-18661 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-18662",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:ecb6661e-c8b4-5fb3-9f9f-1d878a7f5ee5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-18662 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-19203",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:e4c47cbb-c178-5dd0-8bf2-98d2d19bfaea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-19203 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-19864",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:0accc9a8-fc32-5a41-a5b7-6b90eebc0b44",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-19864 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-2332",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:65d37642-3d0d-5b06-b3e2-78f4387101a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2332 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-5795",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:cf6e890f-552e-5e9d-af81-ab8a6eb55a26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5795 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-6790",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:2b4a957d-d3b3-5526-a927-964fd4fc28aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-6790 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-76182",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:2aee5df2-75b2-595c-ad0b-11180da33f91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-76182 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-76184",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:a260c7f8-0b01-5656-8b29-8bd510ef62ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-76184 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-77711",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:d2a0864f-12be-5652-b6b5-f061e8cc26ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-77711 is fixed in version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    },
    {
      "id": "CVE-2026-8384",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:bcc68b33-b209-504b-85d2-fbe257a97582",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-8384 does not affect version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent. not_affected \u2014 Jetty 9.4.62 is not affected by CVE-2026-8384. The vulnerability exists in Jetty 12.x's integrated canonicalPath method that both strips path parameters and normalizes paths while tracking a 'slash' state variable. Jetty 9.4.62 uses a different architecture with separate decodePath and canonicalPath methods that correctly handle the semicolon-dot-segment pattern.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-58qw-p7qm-5rvh",
      "affects": [
        {
          "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
        }
      ],
      "bom-ref": "urn:uuid:4502db08-a04d-54fc-b12f-1931c8feaf18",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.65.tuxcare0001 of org.eclipse.jetty.memcached:memcached-parent."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.eclipse.jetty.memcached/memcached-parent@9.4.65.tuxcare0001"
    }
  ]
}