{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bed74267-880d-5cfd-9148-345b76c6e289",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.63.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f087c516-5c46-5228-b1c9-626fcd654d98",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b3ac757-7b8c-585d-b90f-356d52764187",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37137 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c181d9fe-2fd3-5fd8-be54-949b2ab97f16",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b590709c-d160-54a7-a508-22c8630bc471",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8b9ede-dd4b-5e0d-bb54-ee164580be05",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e23f25-539f-5ab9-b2f1-a8e3f27d32d8",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63777775-7ca9-5074-b3e1-d31611f00a7c",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a8522c-9cfd-5214-9fe7-a72e3d34f05d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f93d12f-8118-5795-ad22-5b865f4d3e04",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.63.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a41cee2d-760a-5d32-9a54-b8e14c99a128",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bbec61f-1d32-5e0a-b1da-dc6b94903fdb",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ee467be-0ba8-5b99-9ec4-80252bd0f6af",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf25ab5a-31d2-57fe-aa0d-6aa83f835019",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4294bec-d362-509f-9e74-93e87f4f1222",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ad801b-e522-53df-a31d-5ba9bda14f85",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b5cb60c-3b41-5d62-bc90-95cc67df6823",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d491d8-17f9-5901-921e-cccd43d07953",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cfcc63f-9e48-56e8-a822-a7752c44d4dc",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2829165c-33b6-5ff6-a413-ca776063efac",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60cbe97e-e798-5626-b610-32c19ff1c2a1",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680294b3-b941-5fee-be61-0cbc1be8fa11",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c4dc79-bdee-5aef-9e1d-706ad68dbd95",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6314167a-a3ac-5370-a920-21015c1d40b7",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4215ecfc-afaa-57a0-aaf2-20283884bdbe",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ed0700-f98a-54f0-8db1-b8a79fdfc7a8",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bf6743b-8ab1-53d2-b714-643b6fb9a94e",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:651bd345-674b-5c2a-846f-f8fc2e11bd85",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bdfecad-822d-5f23-aa63-a2e27a90b301",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309fecb9-e73f-5f2c-b98a-7f1013f31954",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db3b597-db93-5b8f-909a-512d4f43ef9e",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b4cc6b-0982-5b8e-9bc9-fe41edfa96c7",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e92e5646-071d-5231-a583-912b657abe94",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b3eac66-afc8-5691-b150-93d559cb4272",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00763a54-5055-5d28-93d8-bb29a60c82ee",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94347ad8-74b6-5d6b-beb2-e92ac21c2672",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3bb7641-e97b-5563-9ef7-18bb05b65323",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1f330b2-1f42-562f-a3b2-834241fc2596",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ce6f0b-e392-52a3-b9f2-223a1400cf4c",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0caad036-1441-5b44-85de-bca6198655f5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80538d2e-4d5f-5394-a1f7-d6da006e4f12",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916efa3f-350e-5a59-989d-137e1a8bc4ec",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76aaa2e4-cb19-502f-a232-d2d4834fef1e",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d26d97-2407-551e-91fe-58af390d5178",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45f31302-93b3-5f79-9815-8d1d44426e5a",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1efb37b5-c825-58a1-a311-20bb287441a0",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60d950db-8457-5aea-abf3-0fd7e28fd22b",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6570050d-7e9d-5bad-9a0c-0875d2b9491e",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4be3061-7862-5bba-9500-0ba4e7e2b6bd",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a3b0a6-637f-571c-9c96-689f3929f00f",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8ea516-2bfc-5af4-aebe-54176520a72b",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3093c6de-db87-5c6d-b2a9-21b4635d9deb",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27cb54b2-0d4a-5ee6-befd-234db9c7f925",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f48ca92-32e2-5eb3-b466-fb9dd8943627",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff49f36-8819-50d7-833e-3c5bf8366f5d",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3361cf-8781-5a74-943c-e0b6901e3bec",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c566516b-2b15-5bdb-bcb1-209d5fa1e632",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc5170b-392d-5458-a2c0-3a1071819c26",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa1d01c5-6fca-5af4-a0d8-ddd507b912c1",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2c44886-a69b-5ae2-8e5a-89dc7b900f5e",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ca653d-5f5f-5b09-9dcc-d11db51a09be",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32addef-ab45-557f-be04-10c173814589",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e45b79-e234-57fe-acb1-2f4cbfd7445a",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d5f53d9-d5b2-5849-807c-eb905be94c82",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b75a247-eb01-5821-a688-638f0a4a3c50",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f078a0e1-177d-5a93-9a84-65a794ec23b0",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d622d9-fec8-50a7-a31a-c07cfd7dc3b9",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c584e345-355e-56e8-a9d0-e63dc5eabf6c",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.1"
    }
  ]
}