{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24e809f4-f9f2-5321-8c6b-349a3ef6b1d6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http",
      "version": "4.1.63.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bdee591d-de71-509b-bfbf-137f652029a4",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90267434-8ced-5b16-94d9-ba04e17371ac",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:417bef87-8d41-522a-bcd3-07321fe11a49",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7759ebc1-20ca-591f-a68d-0f3cc6effc30",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30671ea0-3092-52e2-82c8-78fbf9259873",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97478ab-b997-5a3c-8385-d689068c3123",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f55549-be03-5487-9a2f-63bc06491b40",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52dd9eed-c5a8-52d6-9bc0-6921c430cc09",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d008117-c9cc-5aa6-a00f-66c0ac4987bf",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http 4.1.63.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0c5d81-493e-5ec8-b7b4-75131f29295e",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a13f6994-6219-5675-86a2-bf177ad663ff",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a66272-eb62-5b58-a89c-f3de9bffc848",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:538838ed-9731-5e16-a9f9-dba4f2d7d57b",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75f32a89-d1e3-5057-8313-57a6d4d40b52",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13afd7a4-712e-5814-873e-75106fc70c83",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a315feb-c7bf-5f27-bfbe-d05b1cd92d24",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:371e4dcd-8e6f-526a-9636-ef44ef2257c6",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dddd551f-fdbc-58bc-b15f-5bc6aa392f68",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a97fe9-7f1a-57d1-a256-cb10eede1fee",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fdf7b7c-027f-5c46-9779-e3bbe30dc172",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2068b601-7fc3-5837-9efc-cf6a810ec8ff",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67728aaf-e4fc-5eba-827b-df43bc147bbd",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b62f256b-ca00-5025-bc35-a13492096c67",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a97f6e-18a1-5ca9-9c32-8e4f2dc194c1",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c3b268-fd48-5d79-b135-b44fbe006795",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e223156-dc78-5c70-a40b-44e2c5568e30",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9138dec-4ddc-56f1-9a4b-03223329c45b",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14c2593e-325d-582d-b62a-5b86f4f03c0b",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d822c77c-433e-52fb-b3cf-affd19a9a737",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a92a64-e15e-5e75-8cfb-12a905b7a449",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7cdac68-412f-5ab1-8673-f782286146d3",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df18d5af-72d1-5e68-92ed-f41e4af80ca4",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e52e11a-1ad4-59f1-9ab4-18baac756def",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e69477c-a5e8-56c1-b57b-02c4c1085265",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f05b6a8d-b0c2-50c1-9314-e6540f4f2de4",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bcdc08a-5853-5fb9-9309-d825ea1f9909",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e68556fa-a49c-528e-ac93-93f3e928e622",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aafe9e75-7903-5a0f-96b1-cfd31bda2f41",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1da782-f1af-5ec8-b55d-b04554e8f0b8",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe89726-46e4-5f45-aff5-4033864e6611",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131ce70e-b8a2-5539-b8e9-e8d466d0d63a",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73fe1fa-b792-5358-8603-0a3b6f6581cb",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9776fcad-4c22-58b6-8221-db64074cb136",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d02775d7-a33b-5780-8cc4-b86729899220",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb375c6-f8c4-5d27-8100-b18f4cc29ead",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e157c65c-6169-5b9b-b5de-333a45fd5155",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.2"
    }
  ]
}