{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a35124ab-fa1f-52f4-985c-502cad7aeaed",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.63.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3b76f7a4-5022-56bb-83ee-c1ec916940ff",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0c272d-ba01-521d-9d1d-9cb2a59ac0a6",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe3b9bd-d2f4-5e2d-85d1-f07ec5ad6d9f",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f54d53ad-26bf-555c-96ab-6068e2065bcf",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1f6431-d0f7-571f-b3a3-d73e8d6c367a",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:004580c2-5c13-5229-a087-94092c792eb4",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45cb6ed4-25c7-5ced-b980-d2f5e3f9fa68",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3c69062-b09a-53fc-a4cb-14b12ed5eb32",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d312b05d-f44d-5c27-91f8-252892ed6cde",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-haproxy 4.1.63.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c02270d-f25d-51ec-aadb-d9ccd030458b",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9c68d3-fb6d-5b3a-8bf3-3b1a84373d74",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c830d62-dc43-5932-94bc-3e88b463dc3b",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff82f71-10c6-564d-a41f-106cdc0c3208",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d685e31b-0c34-517e-bff2-3421ca1c7a0f",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9550738-dda8-5623-95b1-3a97c9c8a840",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a3ec01d-f444-52ec-875c-f730c2b7930f",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:160d2935-32d9-5c64-8c85-50baa562ff14",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:326251bd-20b7-5f61-b25b-4813e2a3afce",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16be904f-551f-5833-8a8e-59907d74da55",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad63f7ed-889e-5190-a651-b71e6663be64",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea597003-066e-5044-a487-b08bd1071826",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:531d3c3a-a98c-55f0-b704-dde710dae439",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6194cd4f-a64f-5a53-9134-1a30f45f02fe",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fccc20a7-cd0a-5b37-a23a-09969b17eb24",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d62dab-3179-533a-8de6-92966a630c6c",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62751345-aedb-54cc-a40e-edcb649f22fe",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a9579b-d3e1-5910-946f-c72503476f0e",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a07e359-7162-5e4e-9d4c-770b23e78cd9",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca71382-a2c5-5919-8ad3-08fad67d642d",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20347e19-86f2-5aed-8e1d-d267736653d1",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:142b8a57-13b1-54f1-a56e-92a0691d830a",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6ba5ae2-7363-5785-9f50-ab6ac688ac44",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb38defa-2859-58fe-a7b7-a9110ef8b026",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9fec3dc-e3a6-5158-b5b9-44678ae1869b",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6f8b427-a7dd-5d0c-9b1a-3f76b566754a",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e89437-c7bd-5f0d-ab03-23d90ef1adaa",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5546df80-a989-5271-9e85-0c9bca1a8d67",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c18f5a9-85c8-573b-91b4-68a9a9bd090f",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c0232d8-cf0e-531e-b073-8d861b68af43",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9902ecbe-cd0b-565b-b159-3f7c46bab389",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79b022ba-3269-5749-9c25-c14b80d2da38",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:286a9d9f-39cf-52fa-9480-3c1eaf4e33d9",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef28d5a-0566-554f-a2da-f6f14e8cb88a",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670e621f-a056-5479-b1e0-6c108dfa1f21",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db51dcb-3cdb-57ea-a07a-c7fd78b3849f",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0a00f6-5347-5882-af8b-74b3d86ffb2b",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5eb7717-c325-576f-946c-6945d5345ad4",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b01739-f600-5943-96d3-920deacfcbe2",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add00dd9-e1ff-565d-bba0-059f52911a83",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7468ec2c-bc7e-5756-8933-3ef8c50e2055",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60041cc6-00e6-53c3-9f77-11fc54d8a64b",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0ca603-d4e1-5ec7-9127-8272c5b899e1",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5116245-18b1-576f-8e4e-f9b2ce832adc",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915f4760-c895-5b58-b76f-e133717f91a0",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a2cb30b-63de-5a03-95b6-df438e30c7d6",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d8dc8a-bd78-5b86-aed2-b6a93ed537de",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:204b8727-55c8-5c34-b3e3-936379f66dfb",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a3e236-eca6-5a4b-9ac8-836c79f703db",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:603132f2-8802-53db-892c-23244f6e4d1e",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8a4345-3542-5a08-a6bb-22dc23c9a127",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb5a1e5-3f32-581b-bdf0-5cfb023770e2",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d1fa39-7451-556d-980b-a6dad6903945",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e441c5e-f886-514d-94a2-ebb3cc73d4fd",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeaef99a-710f-53f3-9571-e293ccebf47e",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4912ac77-4d9c-51d4-ba75-4240881c515c",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f360653-e4a1-5abf-b3b5-087a7ec2af97",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33750467-a3d1-5e94-ab51-489dced46930",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.2"
    }
  ]
}