{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bc38d179-5d0f-52ef-854a-f1bd4016b62e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.135.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5d2bd471-f43f-5156-ac6f-fa722840ede3",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-55163 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the complete fix for CVE-2025-55163 (MadeYouReset vulnerability). The Http2MaxRstFrameLimitEncoder class is present and enabled by default for HTTP/2 servers, rate-limiting server-sent RST_STREAM frames to prevent resource exhaustion attacks."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfde769c-4ecb-5aae-9ba2-62bb24b4f620",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33871 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 Target version 4.1.135.Final already contains the complete CVE-2026-33871 fix. The vendor patch (commit 9f47a7b6846e6c7cb0481789be51788944042b85) limiting CONTINUATION frames was included in the upstream Netty 4.1.135.Final release and is present in the TuxCare repository at the analyzed SHA 445f793ae39ed92ac7ca250dce68cc80b0596785."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:652884f2-41cf-5689-84c7-749ee1f4946c",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41417 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository version 4.1.135.Final already contains the complete fix for CVE-2026-41417. The vulnerability allowed CRLF injection through the setUri() method, bypassing constructor validation. The fix was applied via commit 6eea1bc7ef (May 4, 2026), which added validation to both setUri() and setMethod() methods to reject URI strings containing CRLF or whitespace characters. This valid..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c4f828-b211-597e-948a-79968497faa9",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42578 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the vendor fix for CVE-2026-42578. Commit 137e3fa9079 (dated 2026-05-04) applied the exact patch that changes HttpProxyHandler to validate headers by default, preventing CRLF injection attacks."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc249b0f-d980-54ad-98ab-91553d2c6cf7",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42579 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 Target repository version 4.1.135.Final already contains the complete CVE-2026-42579 fix. All RFC 1035 validation checks (null byte rejection, label length <= 63, total length <= 255, empty middle label rejection) are present in both encodeDomainName() and decodeDomainName() methods. The fix was inherited when TuxCare onboarded upstream Netty 4.1.135.Final, which was released after the upstream..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b3b0965-76e1-58cc-b4a5-74233e8f9f42",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42580 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the exact fix for CVE-2026-42580. Vendor patch commit 756840b17c has been applied, implementing integer overflow protection in the getChunkSize method."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af44dc14-2acc-500a-b243-db77b15a0c81",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42581 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the complete fix for CVE-2026-42581. The fix was merged from upstream via commit d2475645d8 (2026-05-04), which is an ancestor of the current HEAD (445f793ae3). The vulnerability is blocked by HttpObjectDecoder rejecting HTTP/1.0 requests with Transfer-Encoding headers (throws TransferEncodingNotAllowedException) and rejecting HTTP/1...."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d47cce-f27a-52eb-b63f-20e5df7962ff",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42584 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-42584 is NOT present in the target. The target repository at version 4.1.135.Final already contains the upstream fix commit 6f69dc91a22ad4b56b8a9361a1906b17d427d99a, which implements the defense against HTTP response body misattribution in pipelined requests with 1xx informational responses. The fix was included in the upstream 4.1.135.Final release and onboarded to this TuxCare reposi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f6c036e-08af-5ccd-91c8-7472d23cf861",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42585 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository Netty 4.1.135.Final already contains the fix for CVE-2026-42585. Commit 485f11d322 (dated May 4, 2026) adds validation to ensure 'chunked' is the final encoding in the Transfer-Encoding header, preventing HTTP request smuggling attacks via malformed headers like 'Transfer-Encoding: chunked, identity'."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b307d085-e64a-513c-8a1a-4291e673cec2",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42586 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the fix for CVE-2026-42586. Commit 56fe0d58caced3b93c839f4d8c7f7f8cefef73d6 applied on 2026-05-04 added CRLF validation to RedisEncoder.writeString() method, which is the exact fix from the upstream vendor patches. The validation prevents command injection in inline/simple Redis messages by rejecting content containing carriage return..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69571cc0-b252-5849-b277-aaead0e87469",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42587 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains all fixes from the three upstream security patches (fe702a97, 21b8493b, bf78040e) that address CVE-2026-42587. BrotliDecoder and ZstdDecoder both receive maxAllocation parameters, and BrotliDecoder enforces a 64 KiB per-buffer limit to prevent unbounded decompression."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e783d3-b528-5a34-915c-1b9c043cac98",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44248 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the CVE-2026-44248 fix. Both defense mechanisms from the vendor patches are present: (1) early REPLAY protection in decodeProperties() to prevent repeated parsing of incomplete oversized properties, and (2) Signal catching in READ_VARIABLE_HEADER to reject oversized messages before buffering. The target actually contains the refined v..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2720fca-1b11-5e36-9d8f-f95d2a302512",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44249 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-44249 has already been fixed in the target repository. The target code at version 4.1.135.Final contains both fixes from the vendor patch: (1) correct use of subnetMask in IPv6 address comparison at line 152, and (2) unsigned BigInteger interpretation at line 248. The fix was applied via the upstream commit 53c089fca9 and backported to earlier versions by TuxCare commit 86f341aa26."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc58462a-1233-57bd-8da8-6a8a6c5c58ee",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44250 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-44250 is NOT present in the target repository. The target already contains both vendor fix patches (commits e51c64c964 and 728c98b8ec) that implement the maxNestedArrayDepth limit to prevent the nested array DoS attack. The RedisArrayAggregator class includes the depth check (lines 112-115) that rejects array headers when nesting exceeds the configured limit (default 1024), preventing ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d88ac73-2bea-5567-be8f-6151f3897078",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44890 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-44890 is NOT present in this version. The target repository (Netty 4.1.135.Final) already contains the upstream fix from commit bff98ee51b5d0b7ee25fd5005f2169f2a0467efa. The fix enforces a maximum buffer size limit in RedisDecoder.decodeLength() to prevent unbounded memory accumulation when processing malformed RESP protocol payloads lacking required line terminators."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5355ea6-ff8e-597d-bae4-665dc21d45b9",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44891 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a90315-943c-5c2f-8351-272d721b2727",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-44893 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (netty 4.1.135.Final) already contains the fix for CVE-2026-44893. The vulnerability is mitigated by commit c4623e81ab (present in current branch history), which validates TLV length bounds before buffer operations and uses deferred buffer retention."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1851bc97-5617-5a08-b551-f5fd1ebb75c7",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45416 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository netty version 4.1.135.Final already contains the complete fix for CVE-2026-45416. The fix commit 829c885a45fd9f5ba43fe6caf296214b697366fa is present in the repository history and implements proper default limits (64KB max ClientHello length, 10-second timeout) to prevent unbounded memory allocation from malicious TLS ClientHello messages."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebfba674-92e6-5edf-8cdf-77a78b08d63a",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45536 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 Target version 4.1.135.Final contains the vendor's fix for CVE-2026-45536. The fix commit 652663cb50 ('Epoll / Kqueue: Correctly handle receive of FD') is present in the target's git history and was part of the 4.1.135.Final release. The target code correctly handles SCM_RIGHTS messages with multiple file descriptors by calculating the actual count and closing all fds when count != 1, preventin..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bb28dec-63cc-5110-81e2-fba6b1c7ddad",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45673 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final at SHA 445f793ae3) already contains the vendor security patch for CVE-2026-45673. Commit 06eb73d74c3075b35a21d882475c06ac41e8e57f, applied on 2026-06-01, replaced predictable ThreadLocalRandom with cryptographically secure SecureRandom for DNS transaction ID generation in DnsQueryIdSpace.java. This fix is an ancestor of the current HEAD and has not bee..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9dbb553-1442-5fa0-9849-8d1ffa8b957c",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-45674 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains both bailiwick validation fixes for CVE-2026-45674. The CNAME bailiwick check was added in commit 5749d7822f and the NS bailiwick check in commit 6f19adf368, both present in the current HEAD. These fixes prevent DNS cache poisoning by validating that DNS resource records (CNAME and NS) originate from authoritative sources within the q..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c93eb30-5aad-588e-8d64-fdf69375f0a3",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-46340 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-46340 is NOT present in the target. The target version 4.1.135.Final already contains the complete upstream fix from commit cef5395186. The vulnerable nested CompositeByteBuf wrapping pattern has been replaced with flat ArrayList collection, and limits on concurrent incomplete messages (128) and fragments per message (128) are enforced."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0318c851-befc-5544-8a98-794214f9c180",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47244 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 CVE-2026-47244 has been mitigated in target version 4.1.135.Final. Both required fix patches are present: (1) Http2Settings.defaultSettings() now advertises maxConcurrentStreams=100 by default, and (2) AbstractHttp2ConnectionHandlerBuilder immediately enforces this limit on the remote endpoint during handler initialization. The vulnerability described in the CVE - unlimited concurrent stream cr..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69946a64-f068-560a-93ed-bdb6254a9429",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-47691 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains both DNS Cache Poisoning fixes. Commits 6f19adf368 (NS record bailiwick validation) and 5749d7822f (CNAME bailiwick validation) were applied on June 2, 2026, as part of TuxCare ELS security backports. The bailiwick checks prevent subdomain authoritative servers from poisoning the cache for parent domains or unrelated zones."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aff48e0-092e-51c2-952e-4c670573df4e",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48006 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the complete fix for CVE-2026-48006. Both vendor patches are present: (1) the handlerRemoved() and channelInactive() cleanup methods that prevent memory leaks when connections close with incomplete Redis array aggregations, and (2) the configurable array size bounds. The fix commits (ced30adba2 and e51c64c964) are confirmed ancestors ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3366fb77-6fd0-569a-bc8f-3507f230c047",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the fix for CVE-2026-48043. The vulnerability involved a ByteBuf memory leak in DelegatingDecompressorFrameListener when flow controller exceptions occurred. The fix moves buf.release() into a finally block to ensure cleanup even when exceptions are thrown. This fix is present in the target at lines 381-383 of DelegatingDecompressorFr..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c5bcf2-c76f-59d3-94ad-15878f0916df",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48059 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the complete upstream fix for CVE-2026-48059. The vulnerability involves a memory leak when parsing HAProxy PROXY protocol v2 headers with nested PP2_TYPE_SSL TLVs at depth 2 or greater. The fix (commit bd6214fe1c) was included in the upstream 4.1.135.Final release itself, before the TuxCare onboarding. All three components of the fix..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcbd1261-c0f3-5d5a-ac2c-8b7e37394b6c",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50011 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository at version 4.1.135.Final already contains the complete fix for CVE-2026-50011. All upstream security patches (commits 728c98b8ec, e51c64c964, bff98ee51b) are present as part of the 4.1.135.Final release. The RedisArrayAggregator now validates array size (maxElements default 1,000,000) and nesting depth (maxNestedArrayDepth default 1024) before ArrayList pre-allocation, pre..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473c0551-7b34-5a6b-babc-1e5768fa08dd",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50020 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository at version 4.1.135.Final already contains the complete upstream fix for CVE-2026-50020. The fix includes the new SKIP_INITIAL_LINE_CHARS state, the skipLineChars method with strict CRLF-only validation, updated documentation, and the regression test. The version 4.1.135.Final is explicitly listed as the fixed version in the CVE description."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e6587e-3052-5587-9044-5fbb402ae90c",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50560 does not affect version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.135.Final) already contains the fix for CVE-2026-50560. The vulnerable code pattern has been patched: servers now ignore the MAX_HEADER_LIST_SIZE setting sent by clients, preventing the DoS attack where malicious clients could set arbitrarily small header size limits to prevent the server from sending valid responses."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e48ddd3-1a42-593e-96aa-62351e63c86c",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55831 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22adfa83-bbbf-5a5a-bf19-6548cb56a83c",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55833 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70597979-3543-59c3-90e9-4b2775f1deee",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-55851 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd2852c-4c09-5b53-acec-e4974c361aa7",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56745 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef804d41-2de2-58f8-91ab-e984f9c51566",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56746 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f40e36-9f95-5cdc-9fdf-22d707a0dd21",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56817 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6a30c77-a663-5341-83b8-f48f9dc55b8d",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56818 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87d9a703-0e9d-5ac7-bd07-a23dc71d973a",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56819 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee671d2b-4d9f-570f-94ca-3bff29b7eab6",
      "id": "CVE-2026-56820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56820 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4db573dd-c980-515b-bcac-4252b356babb",
      "id": "CVE-2026-56821",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56821 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c17b55-734a-557a-8cba-a54e9b535249",
      "id": "CVE-2026-56822",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-56822 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a13d96-4d08-588c-b228-9539d83d4b08",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59898 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b48ef094-6714-5a18-92b6-a3a5b5f9cf1f",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59899 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cd31159-1724-55ba-a0be-1e1b65de255f",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59900 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b52a8d5b-9632-599d-b4b9-7fc339525f67",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59901 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e00ffc-9338-536f-a4ac-97e5e7b4cee3",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca191f1b-5119-5b6b-9277-82cc0a6da9dd",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbad834f-2216-5fa4-a381-9fc25cf50186",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59919 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6074a9-57ff-5b25-b443-4ea7fccb6f4d",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59920 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1894f419-ea9d-5202-b612-6c59f76a91c1",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59921 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee95a65-d37d-5aff-8267-202b700f5466",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73507 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d949c92-4b6a-530b-9523-f0fa291fac5b",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-73508 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd8428c-d221-565f-b8e4-5a12751bee7f",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de51f537-2fff-578e-a963-8ad67ced7b43",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 is fixed in version 4.1.135.Final-tuxcare.1 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.135.Final-tuxcare.1"
    }
  ]
}