{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24c46a5e-1d40-5146-8fcc-c555049bc363",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-buffer",
      "version": "4.1.73.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1b2de723-fab5-5a81-b433-28a20572679e",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041a068e-27d6-51e0-8e10-d671fac25be5",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4959ecb-70af-5a28-96e0-41773b6662ac",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d89359c-f0c4-5063-9c9e-b71b68455f3a",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2917103e-c30d-5308-b99b-82bfba70a249",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10f7a5fd-1fd6-51ce-9d19-230e8408afac",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-buffer 4.1.73.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e834987e-24f9-5e51-8e19-651ff0c2dc7a",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:437d1549-084e-55b2-8f35-9ad43c59a91d",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3bb2dd3-ab71-55a1-a71d-2099b898e980",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f47ebde-5d6c-54b3-a1d8-9f6050bb72a3",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11169345-9e0e-5035-aeb4-fa1679070729",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a36d39d5-1f03-5168-a7cf-6d954d855c78",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12369e0-17e6-5256-9481-0715ec56d6bb",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8453e9-ec84-58f1-aa02-043c612610d3",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a4361f-572a-5fc5-8968-8af4d9577995",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed7db229-5109-553b-a5f9-fedeaec70aee",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb52081-acb8-5e1a-83e5-5ee6e4b977fb",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562ae4d5-7d8d-50d6-9a7a-64f6ae2998e0",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16cfc55d-66d4-5562-9ed7-422e90121ee0",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6bb62e8-42e5-5fc2-a001-463c966552e5",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6560cde5-45a8-5d1d-80a3-f84525445b45",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df7996a-4a9a-5c4b-ab86-ebb56c5681bd",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38baf88d-a301-518f-89e7-144b91a5239e",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db716f8-e01a-57ca-b1c8-2436161fad26",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa21f7c8-5614-5639-b901-84ef8095f0a0",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e2f37a2-903c-5c64-a84c-77f7f8754aa1",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff10a2a-48c5-5731-bb60-79604fd7b0e9",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3736d07-612a-5c26-a87d-20eed630ed4c",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd097d84-8ab7-50c6-904b-5366b74e9aec",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d46907b-efc4-575a-8eb1-3a6f80fb5ea0",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f5b99a8-bdb0-594e-8338-3b55e4c0a26d",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d370d15f-0a56-5e37-879f-a55fc24f4e53",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b52d2114-bdc3-5a7e-bde5-ba7035a8c2ca",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c79aefd2-f895-5f6a-8cb0-eafa8695b5fc",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d88be39-d3d4-59c7-9885-9430b38e89f3",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a93b5bf2-68c3-5b33-b85a-82767a80b104",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e5ab226-2d3d-5634-bda1-685c1d3e2e64",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90eb8ceb-d17a-5ba7-896a-0fa4db8bb9eb",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28bd455f-ab91-50cd-8d84-1fafdb2b8812",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c641a5a-2f20-5217-b767-fb581dacf9d4",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d1c5bf8-1915-53dc-8857-a3eca5b32265",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096b8ac2-ef58-5c98-8fa7-e5a9ccb29a82",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ff66e3-0892-5fe1-87c5-2a395f10e329",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6776b3a4-4472-5176-8a8b-d4310a5cad93",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aed5f8fe-c159-54ec-b110-ce40a44a3470",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9080afa4-c975-5db5-8de2-058d5210fa5c",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3651a514-005c-58f8-b0dc-7469bd5724f1",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9f9bb8-02e0-5aa5-9918-f35577458b51",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0453f72-870c-599c-bb36-23159bfb01bb",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd82972d-16a8-57f6-aa0f-e453def496df",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37284680-73ea-5c97-8f2d-cf1f2fabe797",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f56778-a87f-51fc-952c-407517370445",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35af5e9-2202-53d1-af6c-114749926c34",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f867688d-9b26-5d44-95d3-8904fd7754a2",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23df4762-5e02-51e2-acde-ae6d14f284b9",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562c760c-c4c6-528d-84c7-670066832649",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6b8d45-cc90-5536-a0f0-0d256994b8dd",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd22f7ee-fc23-5114-8dc6-e1f59c21d8cc",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a8c3f7-438b-5441-8ca3-d3e2a871f69c",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:323fd33d-14dc-528c-b05e-2301d9ccb131",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccaa7b9d-6f8c-5f14-828c-c8ff4e25a440",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c95dbc29-87e1-5682-baa0-76ada0b979b6",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15256d7a-53f1-5a73-b972-2cf110030205",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e0d87d-f7fd-5c12-a1c1-34e3c44f57dc",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1560ad-5e83-52ce-a34c-57df83daa302",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1814e465-f28f-5ac7-a06e-ddd70ed3772a",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dcfbe61-11ef-5148-a6f2-2518bf143bc3",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3407c99-e82e-5111-9a29-373b1ba29164",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79729101-2373-5433-a3db-658cbbe1b3ff",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59ffc765-9640-51b4-af48-51e70fe837c2",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-buffer."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-buffer@4.1.73.Final-tuxcare.4"
    }
  ]
}