{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a9614f3a-aded-5ff3-929d-29118126981f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-http2",
      "version": "4.1.75.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fad4349c-0126-5369-869b-64f8de0afbc1",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f0da80-8df2-5ddc-bb97-906adf786d74",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb175c5a-1391-5a77-8833-918518bc4041",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763742c7-d579-55a9-8672-4e29f7715a8a",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073a82ca-1498-50c7-b025-697524427866",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efc0655f-c477-5d37-be94-f7f711c835d6",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-http2 4.1.75.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1688fa62-a037-52fd-81e5-46fbf0f6597b",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5ac35df-9dca-55ef-ae4d-5afb763c0e2c",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0280b3a-5d0d-5273-9463-118367c5fd8d",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5751f538-9332-540d-8706-dbb8634b19e2",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb592638-b246-5760-ba0f-e0ec7f70524d",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de3d081-557d-5e03-bbdb-573e8bac25c9",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6670abcd-0b68-549d-8642-6fff33167e48",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8565f84-c80f-5231-b374-13437f3c3650",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b8890e3-0a33-5082-906c-922b466eb2af",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d41c396-751b-5bc8-a63a-00004b30428e",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec815bf3-c61d-53f3-ab6c-e444f5144b13",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d328cd59-5c3a-5b57-9eb5-1cf4a039df3a",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79da772-b5d4-5aa1-906c-805046701fb0",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c9e90e-4669-5a72-add4-fecf3bb92cd7",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e5354d-703d-5227-9a93-cc17086a26d3",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581658ee-e996-5158-98a4-043e22c5b8c1",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de116cb-9be2-5ba2-b99e-6c823f7ca894",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea22fac7-6331-5412-bb81-091b106b6a72",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fa657cc-184a-58f5-8adc-17a9e790b185",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2bf9034-ccf2-50be-943f-3fee3358dfa3",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be469577-37e6-59b4-b5bd-837cc72a0e49",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3e5676-329d-5afc-9e9a-b0d97cae2f59",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c692056-3d57-5488-9ae9-9e6d43abd751",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baffed03-e60f-53b5-9422-a9fa26df33ab",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:138ed0d3-e785-5c0d-82c4-6187cb4481ec",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe813a6-c200-5085-b286-b3fde3171cfa",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b2b64e7-5317-54b0-bcbb-08899808e43c",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1267a754-f084-56ca-a775-07b08bf7e8cb",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c136ffe1-88c8-5837-8ad1-7894d93ca0f1",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dadc2d92-5588-57b4-842d-635db4a427b5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e79de76-e0d5-5ee6-9d77-e49ab775f160",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0681488-ae95-5d95-93d8-1670e46ce07c",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005f0e11-aca1-5e57-9dc2-fe52678d8a36",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82184e58-7c72-5204-978c-08ed9b0860c7",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9416631-1691-5faf-ac14-8c3481b04044",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d9ab1b-83b6-5fe5-9118-a5aa529ea146",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4d65c0-a2f3-5ed2-8bb6-c1ec602c32e6",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:264b0077-e04c-53cc-9bc6-dbcacf08d508",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca67b82e-4b9f-5433-9c70-6b42e363d7d2",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:373900dc-6893-5551-859b-01ae11cdfdf5",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:181bd394-5e64-5cb3-bba6-9234143fb97e",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:271cf615-23f7-5e34-ad6f-1bd8db697791",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:064697ab-3c23-59b9-b5ff-aa8e3d4965bb",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcbdaa15-7824-5ba7-b5c0-827c8af1027c",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f5fa008-448d-5451-a016-dc972718fa9a",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:249dc0f6-5c44-5c16-bf0e-bed64091f2de",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c3ec26f-2680-5b28-bbb7-2dff094a39e6",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2153c2a1-149f-5f9f-9f21-0aba63e006cb",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b8a8966-8737-53fe-92cf-91b7f6ccf6f7",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6920c7e-fa33-5605-9137-f23a28392556",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3b2b6e3-d0cf-55aa-af2b-151afb700bdd",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d656ab7-d084-53fc-995e-a340561a3676",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28a24ec-296f-5870-9f22-50b07a81912a",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b22696a4-cc38-590e-9ecb-0d323ada07ce",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd00fb0-c8c9-56af-82db-bf745038abdc",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cceb026b-a6e5-5066-a09e-9f828bd4406b",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:777f360f-867d-5c0a-ba13-27eb4ae537eb",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5661e9e8-1bb0-5783-8483-1d61a17a9dee",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.75.Final-tuxcare.3"
    }
  ]
}