{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e811093-450b-5f26-b6f3-09409e59888c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.73.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98b1c668-1a1b-55ed-adbb-8075b409f1f4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d81c46ca-8439-5105-adab-fd17a29cd1f3",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73dd354f-6e16-53ec-9899-08d0034baef9",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b57e8a-44f0-5c23-801e-dd5f5227fe1d",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d081c234-3b53-5fa6-82d2-0864bdd8c0bb",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcfd0fcb-d3dc-5949-94f7-f60e3ab47bab",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.73.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a82b3f14-c76e-572d-bacd-d1f924739d0b",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ccc42e2-4316-590f-9175-2bfd88da2e90",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f425afd5-050d-528d-90a2-5de14773d733",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce93f76c-b5cd-5d89-9c31-3c447402867a",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2377856-5c5f-5e9f-a9be-d2ad87df08a5",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1343751d-9244-56ba-b22c-7efd53b6b9c5",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44fa5096-7ae4-517e-85ee-ffd6460d3e77",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370954cf-01d8-5ab4-943c-33e12c59932c",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc220d94-0b45-5102-bf0f-ce1330f79998",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21c1bf83-840b-5f23-91bf-048f2aa55844",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6cf4976-e085-5187-9147-17d44cdac022",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e623428-dd36-56a3-a109-415b3e10e670",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a109290-df29-51c5-a41a-f3bd8f7c6b5e",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ef45fe-fa49-51ee-b52d-66de833ee286",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad87cc8-2628-5c35-9da3-18db391372fa",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e61f5539-432d-5cbe-8c0c-538422c824a4",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19afc337-ff44-5131-be83-f0a985fea9a6",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689d0c62-18d8-542c-ae7a-96394ef62544",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e7a02d-2bfa-5e22-8830-3c2bd6f10ec7",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:877b563e-f25a-5b25-98ad-297946d791d8",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04fef5f-3539-5e2a-9c12-688b19da6053",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a372ac-422c-5abc-84f6-8e0817cbdf51",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4516e99f-db49-518e-ba97-f1418d977874",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0826fa42-4580-5ddc-a447-3fbb39518470",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da1ef620-f8cd-5ab4-9b37-7c2b0d2ead43",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653ca66a-69eb-5fab-a131-b0c41417a759",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e1258e9-716b-5ff4-a2e6-a818de088f12",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20f21cc-6221-55da-aa74-7f98a1a8f907",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a757b670-dba1-553e-9181-2e0ce3efdfba",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab5584a-7b68-59eb-a8e8-da25978a0a7b",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021bbc1b-206b-5659-ad2e-43c6efc2605d",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60f98f3-f2d3-5e69-9186-e5f5a1f142d9",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6828fb73-3f36-5d1a-a493-80bc8d9d8755",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e37c582-d73e-5091-b1d7-b690c0dade4b",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee30d9eb-2875-577e-9025-fe803d607dcd",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bccd6306-8b4c-5201-9fce-7710ed60d656",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f57f9d-f621-57df-b14c-c0d84df64ec4",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9a7d52-4a35-50e7-984e-e2827c803b82",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e76625d2-9fc7-5df4-82d1-5e0bf578fbbe",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c7b8f48-04f3-5d78-8937-f1439d92267c",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872e88e7-54ae-539b-995c-55b15f6af8d9",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6072f7c-b9ef-5d9e-b589-40b33ad3b732",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bc3b5f7-783e-5bf4-beb3-dd2599347235",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eece50d6-f947-5e76-8821-9e122fb6daaa",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:871b1fd2-a726-5353-baaf-008a16bca2aa",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5278872b-afb0-51b5-99a2-3f4c778b967c",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ae913d-dcf9-53ac-bd9e-942cda527016",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55168398-562e-5c25-a14f-f3a77535e78a",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f03c3b5-9dd4-5599-9f17-90f26d2ab0b4",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaacadcd-db9b-5868-9780-0d660551db20",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:defe5d22-76c8-5f99-adc9-a39a751c29e4",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fbb84e0-869f-55b7-8cb4-ff13ff44b6c4",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:202a8e75-59ff-5a84-9faf-56c7db1934ae",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c88c5c-8f7d-58e3-a652-eeadfa278e81",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb21b5b5-d2fc-569b-a581-89fadef71bec",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac246615-ed97-5e5f-be8a-dc9c78ee4de0",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41f46345-3bfe-5a70-8fb3-9413a767b1bb",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:056fd7ac-8659-50e6-b776-a144ece38dee",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.2"
    }
  ]
}