{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13b746ae-7e06-5c50-8fae-54f34a6a1375",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-osgi",
      "version": "4.1.63.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f42a608e-74f1-5f4d-8714-b1cccfed0e29",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ad776e-59b4-56d2-a8ec-a4236c93cf3d",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37137 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f659ab9-b2c8-5407-a0e6-f21f43561570",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c9dcc26-7087-52db-9cb6-2a552c900f7c",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d589ee1a-a64b-5867-ade8-f40827ae16f4",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11734c28-3a6f-58d4-ad0d-eedca14eec86",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17de6567-e4f5-5b44-a767-511dfb7e3536",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab31bfc0-d856-504c-a8bf-97ef4a97bf0b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c722af6-810b-5f86-9d30-5515e3f97a7d",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-osgi 4.1.63.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7f0ca85-d94e-5740-bded-e3e3a8fd9cdb",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a4f61d-5a60-5a9a-ac43-2e93fd77395b",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:161f3fbc-7385-505b-b655-7682cbc07ce9",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea49eba-c3b2-53a1-8bf9-8c6315e41a7f",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b24f73-cba2-5ebf-aba2-8b42eaaa78e1",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1289b639-e365-53c2-8e55-7c67e5ca1499",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb868ebe-3516-58df-b842-a42c418243eb",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d78f2c67-66d8-5f8d-a1ee-ceb332264725",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6d9db6-93db-5ef4-b60c-7dd88c660d2c",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e52b290-4beb-554f-84ff-7825244576f7",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e741e813-1b87-5830-bae2-7b37a128b094",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7297e8a3-ce9d-5dbf-af54-5f4e70ae8804",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34f810a3-2a02-536c-859d-96acbaa120c0",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac28f1b-2722-5045-ae6c-0fa820636140",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fec19e3-748c-51c5-b924-3cdbca8c17a8",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8867d05d-c2d6-5506-96c2-5f1be90fb0b5",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:520c5d13-fe36-56b6-8d61-bb6495a1395c",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b22be03d-ea6b-5d1c-a8f5-fc92462ddb78",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6537a8c9-d459-546a-85ee-290df81b9803",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1193a24a-326d-5db2-b276-b14c88558517",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c2593c4-ba05-598d-adc8-7fd76abba0df",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9150cdb-1dfd-587a-abe4-f2183e49de10",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a49e14a-33f4-55e1-acb1-80cebd0dcd92",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e70e7b6-e79c-57a5-95e5-770bfe0d0329",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc434334-1979-5c7d-8532-dbdeeabcd064",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1c1b7c9-89ad-5d79-b55e-d661d4cc30ae",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d157de3d-f1f1-5d2e-a6c0-c3c8aa3f851d",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05ec310a-12a9-5505-8ba2-98f732b5f1c8",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e3b7b8-2ca9-58a6-821d-50b1923c10e9",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89ef5aa4-66aa-5e4e-80fb-cdb48a2e5777",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1acfdc1-6860-533b-8f9a-01bcec41189d",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6782cb85-0b11-58a5-b0ee-1b314b4932cd",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69677dcd-a820-55bc-b8c4-45bbe67d2f6d",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:552ca2f6-b07b-5add-b257-dee473b81d28",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19aad1df-9e37-5095-a433-bf1665a257f0",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52185d4-6dec-59fa-8ae7-ecdf1228c635",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1548f2-9169-5675-9763-820ed0c92777",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d08317e1-93ca-5946-8f9d-3b2e695fda5c",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9f58e5-c843-52a7-b170-2516294e2984",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21c23e99-82d1-585b-a8ce-edc8ef880c1d",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecfd59d1-2d47-5ece-afd7-f73693d2ffb5",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c3b5ce-604e-5c0a-bb99-2475bd1f1f95",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ccba880-4f04-57a7-b05e-d7478a8d516f",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2333a924-f680-57ba-8e84-bfcdf6cb700d",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d85d4a44-fad6-5d47-9db3-b5796d2bbf59",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e649572-17a6-57c3-aae1-60f31b34ad56",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5015d8fb-101e-5f31-978d-9022dedc28bb",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2370da1-a022-570c-a896-d21a1821606c",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ace17c-2fbe-52a6-8cd3-0dc2ca913984",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af135486-0036-5d91-b5fe-9e86bebc16ab",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86727ad-6a84-5cb9-9fc4-1fd6824f00e2",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6724cc0b-f49e-54eb-b234-8584b17f3739",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce95b421-fe5c-5d61-8c67-d07babda3520",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c994ed-ce09-5895-bb74-6630cd06194d",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4927bd99-1b26-5480-a477-d7dae0cf18cb",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c65f695-18ca-5b58-942a-f5c23aaa05df",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d67cd9-5e0b-5e9b-8abf-04f613bbd93a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8194b80b-a2c4-5cbc-a420-617896cac090",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.1"
    }
  ]
}