{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bd3f59c1-3a1a-506d-9329-658f0f83a145",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.63.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:363c3751-a9a2-513c-b81d-1eb030aeb77c",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b89c6730-9e59-5276-b7ce-009116a1c45e",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37137 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:227592e8-08ac-53d4-ac05-ee3b5b999ce5",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e7076e0-71ce-5196-9cde-5b8bd2dec09c",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a33d8c8f-80da-54fa-97f3-aacbb9e8a2ae",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9cbfd85-7853-5b0f-b5cf-0cae78268074",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:328ff52a-b19b-5df3-8e69-be0fd3a98e52",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d0fe267-80f8-5d51-91ec-3e0a33a86e25",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46d87692-9d67-583b-947b-b9c383b124e1",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-haproxy 4.1.63.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd93495-2230-5088-897b-7982e6aef597",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7279e246-fc10-5441-833b-98c486dc748c",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42d2b7d-3d94-5fe7-8cc3-cb3b41f2b075",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b75a3b6-f2bb-510e-8a19-653f6fc72852",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e722fc-6c20-5b3b-9263-6adcb16c1e07",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:182b00b8-7d40-58a1-8863-e777d00c0ff0",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0edf9e5f-e0e7-521d-9cc0-7ed6f90114bf",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ff27452-c65e-55da-8df0-abcb5fd5a3ce",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf906a4-2a98-5bd6-afab-5a096fdea1e5",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b5b991d-9ade-551c-94a0-58dd0745f6e0",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa6ff5ca-bdb2-5282-b508-12f614338795",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:254c7ba6-ba61-53e7-822a-49d085282777",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd2d9f9-5d89-5014-ba8d-ec7cc2154b21",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa63374b-a95e-530a-b3ca-b1d476916740",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884e559a-ea60-519d-af49-de2be78c561f",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e46f5307-6829-5783-8cce-34730cc2dca4",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f3e16d4-3155-5282-a9fd-34f49207883f",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1544dffe-5bf8-5de9-8532-c0ebf60c3138",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2b4bf2a-6271-58c0-99f0-966d68c8ae91",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0037322-aed9-5410-a29d-22634f814269",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37a4378f-0d24-5837-8ef0-061311160144",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75551862-7cdd-53b2-8d83-73a35ee1fd02",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32a5041-b4d4-59da-855e-f5acba531de8",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f12febc-24d3-5a1d-a168-d6afe1117313",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db723e0-8858-575b-a761-0e108974f9df",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f59157-70ac-5825-b443-6359a05d8566",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:212d93ed-ce5f-57c5-a16f-d2579f232a64",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11976e32-d889-51a3-bd7c-2a246a31d027",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f952f2-9fbb-5145-815f-4c719b01179e",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0124f06-6e79-5720-a5b0-66cb739b4e78",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ca87d41-bfcb-5b8d-95b6-cc51196e65d0",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c28540f3-0de7-576d-829d-70a1e0673b84",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b33658f-665b-5807-9f16-8a1a813cd287",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b252051-18ab-5a47-9879-2aa5c3dacb4c",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75218f51-ba53-50a2-827b-79708dbce261",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2196d4a-a15c-5718-bebb-ddcfef2a47c6",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66b3362a-0ad8-5178-982f-0f18426628ef",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a52510f-9c90-5366-8770-bef9a76fa920",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e686baab-8c47-5c42-9b53-b70a550330c7",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c330f749-5293-5814-b60a-223c675371ca",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f59ca26-09f5-5a9b-b167-c0ef5532a332",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:accf18f1-ea31-55b4-8224-2b6a2567ec94",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a5641b-ecd5-5adf-a5c8-3ea08e23f29a",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d329c6b-8461-5f26-824b-6e56544f5369",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6d2bee-6da4-54f4-8142-57c3843d2ca8",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9fb0596-05e7-58d7-885a-fef836b20f72",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b5fd14-78f6-546e-a408-94faf850e27b",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:658be4db-2a6c-58a0-b261-ba094c5dad12",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82eb65d-8d64-5613-bc7d-7633b5de6f0d",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0977272f-8c0c-570b-bdd1-285f52a5f6d6",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf85555-7140-59e1-9b17-546673f53a1d",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7476355c-7f41-51ac-b576-5dc83f8af13d",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01f67679-6ec5-5726-bb4c-4c3c8ec0d539",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1545f1-1de6-5e07-bd0b-09d60939e175",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5ad9fb8-20f2-53a4-bb5b-905e256441d6",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1da119c-92e0-5115-99c3-2e10eb5578f7",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5312600b-17b2-5773-aee3-3cd1707044ca",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519f5ade-3860-5383-8eb3-a39bf0ec3c57",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.1"
    }
  ]
}