{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:88722879-3d6f-5318-a6c9-4560b2324da4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-autobahn",
      "version": "4.1.63.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:35594600-8564-5550-abe2-f8cec4ab3320",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1988ddd2-b2ec-5a7a-a816-bdcf6346f48c",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee9e379b-625a-54fe-8479-bb7adde519da",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeeb294f-03a5-58e3-b3b8-6182c34b2a93",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcbaf9e-a1d9-523d-bd05-66a2bb7edb92",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5202f518-a944-5b92-ad24-d4f0f3f46514",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03891a6d-3a5e-52ee-b487-2122cf6b4c03",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1528d45-a293-5209-80fa-8baa6c198834",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce96ec5-c2c9-5ac2-949f-fbd867178bfb",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-autobahn 4.1.63.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67dfe552-fc43-5feb-8486-8d5906b4adbd",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ff4109f-1f9d-5452-a2ef-b2b7c06da078",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39a08e4d-04ef-59b6-b67a-80089f105b01",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43b927df-d1a2-5d3a-8504-4bd41979fa70",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c8ec810-f163-5493-8972-5fa62034d772",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fbb9178-ddbe-5216-aa1e-18230646e0ad",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1a1d5d1-47e6-53d4-914b-0bc3cc6e6f54",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c2c5d3c-ca3e-5138-9880-8e8a43ddcdc5",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae143e2-b881-535f-a374-a944eba94fc7",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602575a0-81e8-5689-839b-7d8138af7c48",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478930e3-8f27-5bff-b0be-10e16b010f5a",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01c3ee2-66db-5c7b-9420-2e6ff4737a7d",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:270ed030-ef8e-5a47-be7b-3dfcabc65012",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57318ce7-add5-5cc5-b016-4701a75fff1d",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931409ca-3718-51ec-92c0-584cccf0bb63",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a42261c-e139-5907-8100-db79324b51f6",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c563a0ac-ab4d-5ab2-8eaf-da88bcfc8ff5",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c9fe92-a1eb-54ae-864c-545100668176",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1121de-9eda-52b2-aafd-5d5fb89ae2a6",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8969fb8a-9e88-5cad-9a17-499cc94ad841",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a3b856e-d57b-50d7-9fda-8f99fe6cbac5",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7c4262-926f-5f3c-b897-77414592a3fa",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2aafb90-a216-58d2-8cc9-aaca0463d60a",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd4fe33-27d1-55e6-a664-ea07d5bc55ab",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcfc01e7-473f-5044-903e-34a3498ae1f8",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52b8a46e-0010-51c5-972b-9377ce85668c",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19018cca-4ba0-5ba7-a9ca-4e814c440544",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:161d6628-6896-510e-9477-bd6a6da2652a",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c47d764a-ce2e-5eb9-905e-882b9099d871",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57699ea2-c94b-5792-8ca0-fef72c7f11e4",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3df3319a-59e9-5cdc-8ca4-6ad0c4c08483",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf36add7-e944-558e-9a8e-2cf5a3557049",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:955d5ffd-501f-53e2-839d-bf2f56518460",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77bfe03-4356-5c39-8b4f-2d2b8c4b2fe4",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f280fe0-5926-5429-a6aa-61506d6f0c67",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:515048ac-f3df-5a55-ab8b-3a6dbf1dc6c8",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f588fd-9210-503e-8c17-50965411d3e7",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24fa769b-86cd-5b5a-a06c-35750353f30f",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1364e49d-4ea8-5714-809a-48c841e6334b",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:303fbee1-ece0-5c48-ba58-e9abda3ff4bc",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72190f6b-5e5e-5f1e-b8e1-d07af04bdf42",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5412b670-e05c-5f23-8a4a-8dcf66421878",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57430399-4924-5be6-82c4-cfde6e42a229",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c97dbf-1edf-5252-9a97-dc20c9805a47",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b825a0-4108-555f-b0fd-c7ba0d839d84",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52c91d4d-518b-5123-b01a-db3c766493c3",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83869600-d944-5b29-a83a-c24d22a545e6",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71aee363-892e-512a-8107-7c4f738b96f2",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22049cd-473e-593e-ba95-b54df6408eac",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be22b2ed-5ef5-55e2-b7e5-25217af317ec",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd60c0fa-509d-55e5-96c2-3e51896db5f2",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8e98fc-adac-581f-8962-dc67d1702067",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:504e7d5c-3cbb-54cb-b09e-8fd1ee55ba3b",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a83791e-dcf5-5210-982b-51cb3ae1802e",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5147f60-6cac-5192-b174-3ab6adc5edb2",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b4697b-07c2-500d-a3a1-e890b213e0ab",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c01fdc8-0726-5734-9cf0-c6761d599a55",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21470026-2dea-5573-a505-aef12c7f876f",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-autobahn."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-autobahn@4.1.63.Final-tuxcare.2"
    }
  ]
}