{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:871e5efb-4492-50f0-b80f-74eecdc1a73a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.130.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e9262d31-894c-5915-b656-de717c9505e0",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-55163 does not affect version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp. already_fixed \u2014 The target Netty 4.1.130.Final repository already contains the complete MadeYouReset (CVE-2025-55163) mitigation. The Http2MaxRstFrameLimitEncoder defense class is present, integrated into the HTTP/2 connection handler builder, and enabled by default for servers with a threshold of 200 RST_STREAM frames per 30-second window. All protocol-error-triggered RST writes route through the protected en..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f044b92-2208-5cf9-8b96-0bd78283302e",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7aeede-ae2f-5170-ac01-6f4f1500db13",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33871 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41e4e50-9a47-571c-9560-941c334aeca8",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f01a39d-1c57-54e4-b24c-b3f83d60e484",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d6dd10-fb41-5aa4-b468-2a1241234926",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70eac821-3d8a-5239-a450-cab236d0a1a8",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42580 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f6a8bbc-a7aa-53c7-bc9f-c681905a7445",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88ff6291-7576-59d1-b359-c06743ec9f78",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42583 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb858323-6440-5654-bcb5-e3005a6f8806",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b312035c-6bc1-5cc6-a539-cb2d61bbc35d",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:168a3689-5133-5a32-a1b1-e3eef4376245",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65297585-36dd-5283-ac95-fe19edb50c5b",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42587 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896d2113-2990-5fa8-b449-5bbfaea2689f",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b8fcdb-7b75-59f4-a3a9-b1d7ceb96a5b",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9396ec46-3ef9-5769-9a45-c6bf52fd0e94",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:160b6272-d6a5-5fb6-b224-757704c4302f",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692e3130-72c1-5006-9857-578981c17b6f",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b92e168b-c708-5408-a3e8-5704fcdf8bd3",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b36d6e4f-2ecd-5807-a212-478c973efa45",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b3eafb-f052-5523-9954-1fe541e4a7ce",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5939eb62-0fb0-5460-b4d8-6c0db9aa5684",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bba4c2c-bff0-54a9-9509-13acede7dbf8",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2099148-9abd-5a0e-b207-c350141dc100",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40024264-40e7-5692-87cc-76b4cc86e2e8",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5220112-47f0-5eeb-adc1-f050a3420b32",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:549cc930-af6c-549e-9489-c7fa1b3b7769",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39653852-9505-5496-8a5d-d60e6690b936",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48043 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73311b88-b728-522a-ad0b-f97921e69c9f",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48059 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f798fb20-eaf2-5581-a146-c0cb2b986bcf",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50010 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a42231df-5fdc-5b9b-b8b3-97cb2d28f8e2",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50011 does not affect version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp. Patches already applied: bff98ee51b5d0b7ee25fd5005f2169f2a0467efa (already in target via d5b4e38845f5 'Backport CVE-2026-44890 to 4.1.130.Final')"
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2421ed7-1262-5208-9463-f774d70b233d",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50020 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb35e50-3f75-57eb-9ca6-78e7de0fde65",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98234284-4e57-518f-9423-1bbf60ff4f40",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef66c4c6-1718-5e2d-9284-6092b7da40d5",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df7d6d16-ee49-5b9c-bc15-f14b45e6e6fc",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05bda63f-478e-5182-ba59-7c8aa2f8e977",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5504fc54-b5f2-52ed-9b4b-9f5cca938d43",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb3f0cf-3f07-5a90-b22b-14c1819cfdd9",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fccd610b-fc71-5cd9-8585-bd3657d2549d",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56818 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09a184da-675e-56ba-bb64-2f235622aaac",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c136f80c-0588-5644-b7b0-04a5526063a5",
      "id": "CVE-2026-56820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56820 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c78bfb-111e-5f7d-a050-c12967fe8db1",
      "id": "CVE-2026-56821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56821 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f03a511-e049-5cc8-8937-13b35ca6ba92",
      "id": "CVE-2026-56822",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56822 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c97e6c3-61a1-5167-90ad-ba8ee90f9a73",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55542f0a-0a1e-5208-8bc3-cb11ba2b60fb",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f2b371-592b-5434-832d-4580a33326e6",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e38906ab-9389-586d-8144-d3225434c9f7",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2362f6bf-fee3-5204-8639-46942e8eff94",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9df891d-461d-5bee-8aea-7a88ea25ab4e",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:949b0c7d-1eb4-533b-869d-1a665dce2d53",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ddd3e06-7aa7-579a-82df-604e5950d6c8",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c77646-2a6c-5f86-9f5e-1fa36e3c29f4",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f24aafe4-1008-5987-8bef-5dd29536e1f5",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f89034-f4c0-5595-ac6e-62795d46307f",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c904527-18fe-5adf-a6f0-6de0112d7a25",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61916b65-59fe-51ae-9245-f8bb2b590a1f",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.130.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.1"
    }
  ]
}