{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:86c62842-17fd-5959-974a-ec44b958e7cc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.63.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d8c5fddb-dfd5-5a8d-8bdc-32c45ffda405",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f9f53f-e4e4-5029-8d3a-236fee1f2e9a",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:414c7a40-935a-5257-9f87-b9ced18a1d57",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93da4a74-3184-527f-bffb-98a5a1861107",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308441cb-2149-58ce-8bc6-5536d573a7a7",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b833cb-9c49-57be-85b7-31f4daf07dcd",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73e50a18-c2d4-5f40-827f-5957ddba0b82",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b3665b-ef98-50cc-8563-3827e441c397",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d60c069-b81f-59aa-b021-7eb53de84985",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.63.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28cb3fd6-6b02-528b-b30e-0dc3d09fdaae",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c556f6-9dfb-56e1-8493-9d3b2a347674",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b425413-b6f3-5cde-8a2f-eecdbd13e527",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8226a977-dc29-5baa-b452-b3dec08b161d",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:746993cf-cc7e-5df6-aedc-19731db2fb67",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93dd863b-afbd-5376-8332-a6f49cc8f8de",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60442388-5b2c-59ef-9499-4d9b65d6b27c",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3062a158-1238-5b23-b907-bae95ed0dde6",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d08c28f-ec5d-5c31-803c-55d8f380f234",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab120c1-1b41-5f96-9c2d-ae1d69d05b1c",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a4fe3cf-447e-5423-b685-37fb0b535164",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:053e41ad-2e92-55f0-b992-d60aa54cb66a",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bee0e329-a167-541e-b7dc-705089ecb456",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae71ec2e-412f-505a-886a-08ee3971bc72",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a491116-b418-5714-92b8-68cccd8a4613",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde2f495-9603-5dab-9bf1-9eec5b9a5c6e",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7dad2d4-9403-5a5a-8305-f577e1750616",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519fa14c-61d1-50cd-a2fa-23a0edabe13c",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:201cd9ea-2abb-5655-8f5f-21d302f8fcf5",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3938eff3-3256-5575-9aa6-b1eaf8609a90",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:734a44dc-dfea-5b16-af94-7b3d42790f3d",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd134db-30cc-5b76-8511-11a0091f1bd9",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5dbc7db-47a7-5932-83ab-9939cbabc10e",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56532528-0076-52d0-8f4b-16d4e02862a3",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92fbae63-5bd4-59f3-9fc4-6aa33c67d0a1",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbcf3c5-8bb3-5650-afe4-80971d4d99d1",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4f9494b-8380-571b-a387-dbd1702cfd47",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f218e6b-d652-593c-829b-8e9c807d22bc",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0feed67-7b31-5531-be4e-1a69dcc41985",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf5ab38-c1fe-540f-8ede-9b5f4e8c4ccd",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69e86e0b-2f58-50cd-a1a9-3a9c11070ba3",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82aea306-75f9-5b10-b80e-72f4e605341b",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e43859be-d8d7-57bd-82cd-134a91713a11",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8883f6a8-50c3-5fb9-ba36-8e05c4241f9d",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa325957-94bc-5594-bbe8-b21983666b4a",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49ba3a6-4d31-5948-b4c7-8c64ac43205f",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ca8b6b0-ca72-5bc3-9ab6-3b642bdff768",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca289029-810c-5f59-aeb7-49638726f237",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bbcca07-29c4-55f2-b47b-1876aae0d993",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de9805e-b3d8-53b0-b94e-da34b3540ea3",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c97a09d4-026f-5f83-97d5-9a458afbb2c6",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02b83c7-245f-5c41-b073-8dfeb81c8d5c",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011c80c0-7ed2-5a03-bb0f-7f355b8978ee",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d821f7-64be-579c-85b7-8ed36183e55c",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1f1d2c-bdc8-5bfb-aa9d-15b27840b149",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f08f249d-ada4-5da8-b322-2c15ebb3a603",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:056ffca9-7a65-5f8d-8b89-bc918855193a",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692883b7-3b97-553f-99af-06fc7edef506",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d544a13-55b1-5b48-b569-d0174f8ea27e",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76548ec4-e852-5196-9b95-ecc1d1f8dcc0",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39e28de-081b-5d99-8026-592465bd1c47",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8932e628-fc29-5523-9d7e-25012ac9f06d",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14c1d452-3fc5-5b70-af81-797cfe0e24d9",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c13e51e-1246-5b70-be38-44cac4302799",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c70fffe-d206-58b1-bc82-9d143e96bc19",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b917062-1412-53c0-800a-64926101fc71",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e379b08e-3fc7-5ed8-adb6-09e1a368ef96",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c50d261b-5d81-5ed0-af85-fafbced1da24",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.63.Final-tuxcare.3"
    }
  ]
}