{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0cf58ef6-23d3-54f5-ba8d-4f68ce0f0c47",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-mqtt",
      "version": "4.1.49.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:521bf018-c935-5d40-a6e9-7b732eddf91c",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21290 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eb7c4aa-97df-5f0b-af95-8e568f73b391",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21295 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2831daae-ba03-5692-ae4b-16d19160edbd",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26211e63-e962-5aec-845b-b21f741f7313",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7577dd5-806d-5a68-933b-4b29f3dfbf98",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175777fa-ddaa-58a8-81cf-ea26c6e0360b",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b769fc5b-2557-5c7b-9b67-d4f9a2ca2c70",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce16b6c1-1e31-50df-aa32-d08256352502",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f158ad9e-d947-5a10-bf43-008af1be8b32",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8370610-b2ef-5722-9fdf-b1012ae2b5af",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d93d68c-91fc-5628-aca9-0b629aecd2ed",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ec54b1-1136-5e50-9fd9-a5565f7efdd6",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-mqtt 4.1.49.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:649b39dd-f88b-5af1-ba92-00cc59e71732",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7270f2ef-c92b-5bc2-be59-d5fb0a2497c4",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a1eeb29-74b3-5490-9782-8d3297820465",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64af8639-ed3b-56b5-94a0-3f92d466674d",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f6affc-5810-5fb8-a57c-08dc75bcca27",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43ac2fe3-bfbe-52a7-9ebb-b5363bcfd268",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51f82061-5b4d-5ec4-a6a3-01e5997e3db5",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88a5e83-1d2a-5a09-abd6-64657b124a99",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4f6bba-75a5-52cd-b91e-108d4d4c7f60",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a039fa4a-6aaa-55ba-bdeb-e5a6f9343952",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a79bf4-e3ec-56d0-b611-57f1f5419569",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d93aab-6f4f-517d-9faa-6760f9ee0a75",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b822872-502c-5ebe-a639-758f44beaa81",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57faa2ec-8810-58eb-8e89-21812a54b131",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0a65f8-b326-50bb-85e1-bd220bb56174",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faeec0ab-c190-5ce4-bab1-37710803ac25",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:febbb31b-1379-50ea-be7d-00bebdc79cab",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5698cd2-1db2-5cf3-a4e6-1447a24cb74b",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b31c8d-f03d-5753-b632-4efdeaa41926",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cbed2a3-45d7-57fb-8223-6ea7b620b0a7",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d79fe5-df6b-5504-a61f-03f683452653",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de51e09c-0ad2-532d-8b86-af28c0a54ee2",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab74459b-2432-5991-90da-f41e631ad7cc",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b052683a-a175-5d22-a238-974b5570eda0",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e71c13-6f89-586e-9d15-4159afea39ec",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f989886-c5c6-5ed1-b54c-3699a2e8c7e8",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b46dc89-9a6f-5bc3-af0a-b68a833f7412",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e991c8e5-d169-5947-9c26-4d7cf8bfc889",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca312680-bf2c-5d35-a3fd-7eb4dfa1641c",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9bd907a-fe44-5fc2-a979-cbcd7993a9e6",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:339c2484-7be2-5b6c-b564-233ded8cb577",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4424f0-16eb-5155-9b9a-c8b328978e3c",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50604954-4290-5409-b2b0-91ef568dcd28",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77f6303-ad3a-5c80-849c-a63a3e6c1ddd",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46580e35-0251-5bb2-b07f-41ed5a7ebc8c",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b845ac3-6b6f-55eb-b311-50b2560e25d1",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6cda7ba-e041-56fc-9730-83c9ce015e37",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
    }
  ]
}