{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:be701e08-1b3f-58f9-8d53-8a9fe901e47e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-osgi",
      "version": "4.1.63.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:52cc1fe1-1601-51ec-90cb-2042e0548120",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab1e14b5-07ca-52e8-997a-8dc9a7e14f3f",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55075bfc-6adb-58b1-89b5-0ee5c24313cb",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77397353-a938-5298-aafa-7008b020cc33",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3910416-bc35-5a39-b4f2-91fa7edcdd7d",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8fe85d3-ba3c-5221-9d26-dbc32d4b938c",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d3a4d3-87c1-50a5-9cfe-f0a32c4a939e",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97700d42-09da-5ee6-ab54-3fa16175bc0a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:774663f9-25c0-5b2f-84b5-809ccbd1c6b0",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-osgi 4.1.63.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde62d04-4cbb-57ec-b660-5103446c2abc",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffda1dd9-4da6-5106-9485-351325c6808f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63a87153-2695-5c6f-a165-cadaf7e29e41",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9fc157-35cb-5093-aadf-687dac13b3f7",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1cb0c06-0dea-53c2-a4bc-d74c240a3c0e",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc45e92c-f3fa-5362-94f5-df5bcf27fb96",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2799932-8e5b-5293-a0f6-228156ca02ef",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f04a4504-2aa3-5231-8fcc-d95e35f97998",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30fcc834-9546-5b37-adb4-c12eb9204e9b",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9345db-cb82-5e92-a814-7d94f070f4db",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3becbe40-2174-524c-b739-d37f82a6346d",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170e70b7-8762-5053-a54c-e89d4422fcbb",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5beba0b-20e5-5a32-a729-d94797787a64",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85569999-c37d-5bad-9ac2-dc394a812be9",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d9f8bd-5217-5a91-82da-fa6735c64bd3",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c1cbf6-b96e-57dd-a9f2-1362d2a12582",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67b90c1-fd93-5eef-a959-b759fdf0633e",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe0036e-e57e-5de7-9072-b99cbaafe45d",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d91c67c9-b608-553c-9211-e2cb3941a5b6",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f665c694-adf0-56a8-8426-70cc6d651530",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad400ea3-192f-5ccc-a14c-35c5df56ac00",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cffc17b-c160-5ef4-b357-2f0fde88cab8",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:290dadf6-9f47-5223-8ad6-a4d1abf9d0d6",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06bdd64d-8803-585d-a147-9a8892325922",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82acd6da-d52f-5b55-a10c-03f5d8c04ab4",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6cfe434-3eb4-5fe2-ba51-88fc79731960",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53b797b3-8f59-595a-90ed-c6d5498e83ee",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1039b93e-f352-59b0-91ce-71de6cf27bdd",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72549785-ecae-5aef-8e0f-3ffc70a4d118",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e21a7cef-8576-534f-9ea5-14202539557e",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51b7a355-9d8b-5bab-8de9-36be1c41f898",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b63b2fca-1b13-5db8-aa4e-50b49f20f285",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3998eee7-acc3-5dae-8ed1-dae30dc63a25",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9432cbdb-6c76-59aa-b42d-1edaa83fd665",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6779050c-f607-5015-a91e-315ec98aa991",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8734850-2c49-5a14-9095-f190f855553c",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ed5c8d-b826-5869-8895-88b1621cab0a",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be6c4083-cdf9-50ae-8d49-947a3ca04776",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c242e75-ebf8-5ca0-9249-6db47f473188",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03bbf1a5-2d1d-5b4b-b2d9-76ed90062426",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615f0561-7b4c-56c1-9890-42f7c83ff2ef",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9623712d-9a0e-5412-a280-b2b6a1b8e51d",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba82806-40af-5fe0-b0be-98104602c4b7",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37204e59-3a00-5d54-8cfa-51acdd87fec5",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b89615-9bd3-5361-9737-e735d98efedb",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17ec253-42de-5873-a7c5-e78656d965c1",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83410c86-7625-5f9c-b28a-75160310e12d",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f36ad07f-c9d4-546d-9ede-1da7463edb12",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a390df-0a7e-58f3-acf5-b14ef7329218",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:403ac8b1-c168-5b93-8e67-f1d031166dbc",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:433485ec-4e79-5412-8d06-ee6864223a7e",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:237bd73d-451b-5e53-ae4d-0152670149a1",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50b0ff0-8cf9-55ed-8182-d3ea30a888fa",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da474c8-e758-585f-8b50-c1995699dbeb",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a054e57f-46d4-537a-9d73-dee4bfa7b11e",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d6ec4fb-ba01-500f-9578-450bd9d73216",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36010434-4159-59d4-aaa5-17885a4e9721",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68c12652-430a-59be-a450-4e5369990fe5",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.63.Final-tuxcare.2"
    }
  ]
}