{
  "@id": "urn:uuid:cfd4db53-3b66-4da6-8fe7-c20a38bd46b1",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T16:08:06.197770+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2020-27216 does not affect version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded. The target version 9.4.51.v20230217 does not contain CVE-2020-27216's vulnerable race condition pattern. The upstream vendor (Eclipse Jetty) fixed this vulnerability in commit 53e0e0e9b25a6309bf24ee3b10984f4145701edb (authored by Joakim Erdfelt on 2020-10-15), which replaced the insecure File.createTempFile() + delete() + mkdirs() sequence with atomic Files.createTempDirectory(). This fix is present in the target's HEAD. The vulnerable pattern does not exist anywhere in the codebase.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-27216"
      },
      "impact_statement": "The target version 9.4.51.v20230217 does not contain CVE-2020-27216's vulnerable race condition pattern. The upstream vendor (Eclipse Jetty) fixed this vulnerability in commit 53e0e0e9b25a6309bf24ee3b10984f4145701edb (authored by Joakim Erdfelt on 2020-10-15), which replaced the insecure File.createTempFile() + delete() + mkdirs() sequence with atomic Files.createTempDirectory(). This fix is present in the target's HEAD. The vulnerable pattern does not exist anywhere in the codebase."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2021-28169 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2021-28169"
      },
      "action_statement": "Vulnerability CVE-2021-28169 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2021-34428 does not affect version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded. not_affected \u2014 CVE-2021-34428 is a Jetty session-invalidation flaw: if an application's SessionListener#sessionDestroyed() throws, the pre-fix Session.invalidate() skipped SessionIdManager.invalidateAll(), leaving the session ID registered in the ID manager. On clustered / multi-context deployments the session stays valid and a user can remain logged in on a shared computer. The upstream fix (commit 087f486b4461, \"Issue #6277 Better handling of exceptions thrown in sessionDestroyed\", tagged jetty-9.4.41.v20210516) wraps the destroy-listener call in try/catch(Exception) and moves getSessionIdManager().invalidateAll(id) into the finally block so ID removal always runs. Target is jetty-9.4.51.v20230217 (newer than the 9.4.41 fix). Session.java lines 942-958 contain the exact post-fix try/catch/finally; git blame attributes the catch (947-949) and the invalidateAll-in-finally (956-957) to the patch commit itself, authored by Jan Bartel <janb@webtide.com> (upstream Webtide). The fix is stock upstream baked into the onboarded release (ancestor of both parents of the TuxCare onboarding merge; not introduced by it), not a TuxCare backport. Verdict: not_affected \u2014 upstream fix already present in the shipped version; vulnerable pattern absent from HEAD. Justification: code_not_present. [VC re-run with claude-opus-4-8, prod pin d46bd7a, 2026-09-23; the earlier Sonnet run was parked by the author-verification gate after crediting a TuxCare backport for an upstream fix]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-34428"
      },
      "impact_statement": "not_affected \u2014 CVE-2021-34428 is a Jetty session-invalidation flaw: if an application's SessionListener#sessionDestroyed() throws, the pre-fix Session.invalidate() skipped SessionIdManager.invalidateAll(), leaving the session ID registered in the ID manager. On clustered / multi-context deployments the session stays valid and a user can remain logged in on a shared computer. The upstream fix (commit 087f486b4461, \"Issue #6277 Better handling of exceptions thrown in sessionDestroyed\", tagged jetty-9.4.41.v20210516) wraps the destroy-listener call in try/catch(Exception) and moves getSessionIdManager().invalidateAll(id) into the finally block so ID removal always runs. Target is jetty-9.4.51.v20230217 (newer than the 9.4.41 fix). Session.java lines 942-958 contain the exact post-fix try/catch/finally; git blame attributes the catch (947-949) and the invalidateAll-in-finally (956-957) to the patch commit itself, authored by Jan Bartel <janb@webtide.com> (upstream Webtide). The fix is stock upstream baked into the onboarded release (ancestor of both parents of the TuxCare onboarding merge; not introduced by it), not a TuxCare backport. Verdict: not_affected \u2014 upstream fix already present in the shipped version; vulnerable pattern absent from HEAD. Justification: code_not_present. [VC re-run with claude-opus-4-8, prod pin d46bd7a, 2026-09-23; the earlier Sonnet run was parked by the author-verification gate after crediting a TuxCare backport for an upstream fix]"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2023-36478 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2023-36478"
      },
      "action_statement": "Vulnerability CVE-2023-36478 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2023-36479 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2023-36479"
      },
      "action_statement": "Vulnerability CVE-2023-36479 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2023-40167 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2023-40167"
      },
      "action_statement": "Vulnerability CVE-2023-40167 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2023-41900 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2023-41900"
      },
      "action_statement": "Vulnerability CVE-2023-41900 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2023-44487 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2023-44487"
      },
      "action_statement": "Vulnerability CVE-2023-44487 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-13009 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-13009"
      },
      "action_statement": "Vulnerability CVE-2024-13009 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-22201 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-22201"
      },
      "action_statement": "Vulnerability CVE-2024-22201 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-6762 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-6762"
      },
      "action_statement": "Vulnerability CVE-2024-6762 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-6763 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-6763"
      },
      "action_statement": "Vulnerability CVE-2024-6763 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-8184 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-8184"
      },
      "action_statement": "Vulnerability CVE-2024-8184 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2024-9823 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2024-9823"
      },
      "action_statement": "Vulnerability CVE-2024-9823 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2025-11143 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2025-11143"
      },
      "action_statement": "Vulnerability CVE-2025-11143 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2025-5115 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2025-5115"
      },
      "action_statement": "Vulnerability CVE-2025-5115 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-10050 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2026-10050"
      },
      "action_statement": "Vulnerability CVE-2026-10050 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-10051 does not affect version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded. not_affected \u2014 Jetty 9.4.51.v20230217 is not affected by CVE-2026-10051 because the vulnerable pattern (trailers not being cleared between requests) does not exist in this version. The CVE describes a vulnerability in Jetty 12.x's HttpConnection where the _trailers field was never cleared between HTTP/1.1 keep-alive requests. However, Jetty 9.4.x uses a different architecture (HttpChannelOverHttp) that proper...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-10051"
      },
      "impact_statement": "not_affected \u2014 Jetty 9.4.51.v20230217 is not affected by CVE-2026-10051 because the vulnerable pattern (trailers not being cleared between requests) does not exist in this version. The CVE describes a vulnerability in Jetty 12.x's HttpConnection where the _trailers field was never cleared between HTTP/1.1 keep-alive requests. However, Jetty 9.4.x uses a different architecture (HttpChannelOverHttp) that proper..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-1605 does not affect version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded. Jetty 9.4.51.v20230217 uses a fundamentally different architecture than the vulnerable Jetty 12.x described in CVE-2026-1605. The CVE-specific vulnerability pattern requires GzipRequest with InflaterPool where cleanup is conditional on response deflation. Jetty 9.4.51 lacks these components entirely (GzipRequest, GzipResponseAndCallback, pooled Inflaters) and instead uses GzipHttpInputInterceptor with direct Inflater creation and deferred cleanup via HttpInput.recycle(). The specific chain from Input to Goal (pool exhaustion leading to permanent memory leak) is not reachable in this version's architecture.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-1605"
      },
      "impact_statement": "Jetty 9.4.51.v20230217 uses a fundamentally different architecture than the vulnerable Jetty 12.x described in CVE-2026-1605. The CVE-specific vulnerability pattern requires GzipRequest with InflaterPool where cleanup is conditional on response deflation. Jetty 9.4.51 lacks these components entirely (GzipRequest, GzipResponseAndCallback, pooled Inflaters) and instead uses GzipHttpInputInterceptor with direct Inflater creation and deferred cleanup via HttpInput.recycle(). The specific chain from Input to Goal (pool exhaustion leading to permanent memory leak) is not reachable in this version's architecture."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-2332 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2026-2332"
      },
      "action_statement": "Vulnerability CVE-2026-2332 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-6790 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "CVE-2026-6790"
      },
      "action_statement": "Vulnerability CVE-2026-6790 affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability CVE-2026-8384 does not affect version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded. not_affected \u2014 The target (Jetty 9.4.51.v20230217) is not affected by CVE-2026-8384. While the CVE describes a path normalization bypass in Jetty 12.1.8 where URIUtil.canonicalPath() fails to normalize paths containing `;/../` patterns due to incorrect slash-state tracking, Jetty 9.4.x uses a fundamentally different two-step architecture that prevents this vulnerability. The target's HttpURI.getDecodedPath() ...",
      "vulnerability": {
        "name": "CVE-2026-8384"
      },
      "impact_statement": "not_affected \u2014 The target (Jetty 9.4.51.v20230217) is not affected by CVE-2026-8384. While the CVE describes a path normalization bypass in Jetty 12.1.8 where URIUtil.canonicalPath() fails to normalize paths containing `;/../` patterns due to incorrect slash-state tracking, Jetty 9.4.x uses a fundamentally different two-step architecture that prevents this vulnerability. The target's HttpURI.getDecodedPath() ..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.eclipse.jetty/infinispan-embedded@9.4.51.v20230217-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-30T16:08:06.197770+00:00",
      "status_notes": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded.",
      "vulnerability": {
        "name": "GHSA-58qw-p7qm-5rvh"
      },
      "action_statement": "Vulnerability GHSA-58qw-p7qm-5rvh affects version 9.4.51.v20230217-tuxcare.1 of org.eclipse.jetty:infinispan-embedded."
    }
  ]
}
