{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:20e6bf60-2231-5c73-adb8-a1aa49fe9ade",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.75.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f40dc12e-3f27-5e1b-aa64-760caa79f766",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c0d7f5-052c-5544-b883-e21ce077d170",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996fa5d7-ec53-5a17-9cd4-df3d95f651f9",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41818a9-d146-5014-b669-3f5c4feb3eb7",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec6d69c4-398c-589b-8a02-740781b3823a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287f08e6-f585-5a72-9a90-0be3941ca43c",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.75.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7378f2-72d3-5595-b150-cc12cdd2a983",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4afe640b-7213-56de-8093-8ec78f856aca",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af9ef600-11f2-5083-b440-4bcc49a81d9d",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd7c783-48f9-5a31-bb1a-d712d6608732",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64b37ada-e428-5643-b70e-b84da9e84c98",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c77ed9b-73d1-5e84-a19d-fb4fab9477c8",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021c5ecd-0fbd-5659-aa56-7253291f11c7",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c96f9d-5499-5c83-af7c-004f68433dc8",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a537792f-b169-58ab-b12a-42ec5e753ae4",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8be40ea-40a6-5069-aa7c-93013760bbca",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:addee164-8363-5f00-8e6a-bc7e91ac48f4",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ada11ea-86fd-5b25-876f-c98d02d83a54",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc550e83-4119-5062-b373-075da9fa3ad6",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdaaeb79-7f48-5aef-86ce-e325e9db6a65",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:291aa4ae-f2ca-5bd6-903b-9839c4439cce",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ec59b5-36b0-5341-bf30-788ebd0e9974",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56509e10-1d0e-55a8-928d-61ae7dd5b6da",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:758900e4-4a3b-58b9-acb1-33e4347cd05a",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d76bd161-0d78-5ca1-9ee2-b6b9e1a06a3c",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4de124fe-87a2-5697-9d16-441e3c681f92",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4268aaf-b30e-5c78-ba75-ac550b1bbe9f",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4cbbcfc-ce7b-51c8-b151-a524f93e7fe6",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9beb3768-78e9-5c41-9789-b9472c0a0301",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3afecf1a-e26d-5ff8-ac4b-b80eb6d62dd7",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3716720-162b-5a7f-9d74-a9c07b75dfa5",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d457f03-0179-5e3b-ac9f-b65b2a9a2a05",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05c0381e-1c55-519b-bcc2-699978935fb8",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7681eede-889d-5afd-8bdb-dd0163b2b4a0",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7bc511b-36d9-5597-b8a8-b3515946f3ea",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df8deb49-c673-59c5-b38e-5b9676b96f0e",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9366e97-7a17-53b0-90fd-54d406940654",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a32095a-c5a3-5129-807c-59ddfad1346e",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e915c2-dd7d-57e9-ad42-46e3ee384c1a",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f1ad0a-78f1-5eea-89e4-ab516119e838",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5bc4db-5cae-5d66-bd7e-71e2bcad38ed",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd9919ce-1bd4-573a-8382-c4e9fd20b04c",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c91460c-4efe-5233-8c25-47eee54e64dd",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77574962-7221-57b7-995b-632e92ab7cde",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68dc2a3-5e6e-569c-bc9b-bd9dd31de2c3",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:079c87a0-530a-5366-8124-4d50f0c4ff16",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9985224-413f-5c6b-a01d-91c526058002",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17375188-0405-546c-b315-da8a5e8cc1cc",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d570063-ebe9-55f4-98e2-a41fdab81e04",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c29dc6b5-8b7d-5588-a03c-459619068776",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b65e28b9-85fc-591d-a291-b8a75b679bba",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0df261ac-1fad-589e-8ba8-396fbe5b150e",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b1efc6-7bfc-5307-b9c4-c3f5fdd206ab",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4687a1a-0217-533a-8d07-c44607b54236",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:601f51d0-ea5e-572a-9e27-ab5fe3d1fb2a",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef07fa6-0cab-5bc9-a851-a1494f03a02b",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0eda16b-bf02-5256-8029-2cd6cbc651d5",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64ecda8-6ab2-5691-bc4f-cc477eaa06b8",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b28a8ae-09b3-5246-8d14-95e569a59e3c",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04221641-8987-58c4-b156-2917d97107c6",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:353e84ad-3cef-5f70-8f17-ef863fa61d50",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6583dd0b-85c2-5ca2-9646-af54f6f252b2",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f280900-e8d0-54c8-8cf1-a7a1a8d8d854",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c9d650b-6218-53ca-acc2-07b145fc5354",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.75.Final-tuxcare.2"
    }
  ]
}