{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e0fb7a95-f5c3-526f-8968-6a92b15ac787",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.75.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ee471612-c7dc-5e38-bc7e-5f8d596a9fcc",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013ad646-d68d-50d7-b634-bcf0c5ff6fde",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3a604ac-9d89-556b-9a3e-e29d87152ffc",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e2baf0b-4af8-59ab-9828-202c6077d480",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b142f401-28a7-51ee-8fc4-ebb4dcdb228f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a43a8ac-22eb-58c8-95c8-7e7921c61cc5",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.75.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbc94163-4e8b-54ff-bd53-164ec0f1aebf",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc4dd61e-795b-572d-b050-81de7e965181",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd1d5098-22fd-5e75-a443-4ed9fd61012a",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f5670a6-ee74-5b4b-a16e-f5bf2390f6d5",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fcd244b-e1e3-5eac-aeb8-16e4a268209f",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:554e2c29-f789-56a5-b0b4-c231352b410a",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32badb72-cd9b-5fd2-bd21-3614b8883d75",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ede2a99-1bb7-5c4f-9428-dc153d4f0f58",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61d85599-28b1-5228-89be-b345d76c65bf",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:579dd24a-ee3a-517c-bf0e-9aea9de530e6",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eb288e8-64e6-5419-a2aa-77b9010b639b",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c95334-9f84-52ba-968e-21fa0de26f2c",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:955587f9-6da4-506a-a42f-d5616101756f",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d199271-d613-5d1e-9095-b341a95b0346",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:511b5440-4657-5136-afaa-ca4b64cb87be",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a847c0-ab17-58b3-a647-52ff43bda1d1",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52525d96-ec88-5908-b5a9-af371b637289",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de7fe0ed-08e5-5dfc-a3c4-b1d95bd68864",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79dfe2e8-3adb-5910-9cd3-dee3b858bbda",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30a520e3-622b-5763-92de-4fc2a1bbcd2f",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b6d378-18c7-555a-a442-ee4cdaa9b9bf",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59a7c7bc-a608-5757-a857-0e93d3902e55",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:086732d4-ff22-5a4d-8e61-5f5a7f6930b6",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dea0ecf-cd2c-5f3c-b1fd-b0b0f5ce9d55",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:614de7b7-e329-5664-b4b0-fb1a94863cdb",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74664ccc-3e34-5f4d-980b-02825d46ef47",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be94b98-d369-54f0-997e-3c5d53353e19",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34afb102-293c-5529-93e2-487374674e6a",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4365481f-628f-5d3e-9fb5-d72a35e3269e",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c4e993b-1c9e-54fa-830c-8976727958f5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5726b3a5-bf4c-5e98-9c38-14b31144ba22",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:213820fb-8e87-5c0f-a7d2-e25ececf3f27",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f79927fb-6be2-5aba-8b9a-374419a80d12",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc14f45-7d2f-5222-84a0-fcdc43aa4204",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7bb5aa-f995-5cd1-b8a6-f8c1dbb6a125",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:424d8300-4c52-57fb-ab97-506906fbf606",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:693c2bc1-b19b-5b00-a205-b049e783b8a5",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0ce42da-bae7-5887-9a94-e6226986f9fb",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47d6454-5bfd-5540-8b2f-91c66836ba6b",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c4b05c9-e80d-5afb-a14d-cdd2450b7e61",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec0acc6b-8967-5b61-b25b-37f36b50db17",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bdbebc7-2635-5fc0-9c7c-f8eceb11df4c",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92e8735-3a3f-5043-a332-0faf10e9416e",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6c340c-cb4d-5636-b748-46309bcc5101",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dd2133f-8be1-5ccc-9fd1-b8612ac98fdf",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b989022-b745-58dd-9199-66b90b5d35d2",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:455b60d6-63d7-56d1-816f-168e71b3b7b7",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8050d36-1187-564c-a545-66d1babc2564",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d75a81e3-8419-500b-b0c3-15e3866f62df",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d13f32f8-18a6-5b3e-937a-51ef1f7b1a3f",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22bcb26-c9ec-5874-a018-d8c222aab15a",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cef0770-c6b0-5cf2-a01f-6dc7d91f3800",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82cc9b7a-2736-57fd-a6e6-6e4c2a0a96d6",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c05c3b-fa4a-5f50-beac-eed000998d70",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7ae306-cc2b-5567-9327-a98dca0b1e7f",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:364157d8-104e-59e2-bb10-15ddd1b6e877",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d90ae361-cb8c-512d-a6e7-a2dd29f3591a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54df1b88-ee16-5755-bd28-ce6df2472fda",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.3"
    }
  ]
}