{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2997e31d-af64-5f44-8e25-dc4151c7259b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.130.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:50811db7-8352-5365-b68e-c7bc65a94d12",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-55163 does not affect version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp. already_fixed \u2014 The target Netty 4.1.130.Final repository already contains the complete MadeYouReset (CVE-2025-55163) mitigation. The Http2MaxRstFrameLimitEncoder defense class is present, integrated into the HTTP/2 connection handler builder, and enabled by default for servers with a threshold of 200 RST_STREAM frames per 30-second window. All protocol-error-triggered RST writes route through the protected en..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad83543-d9eb-59db-bce2-1e0b916be10f",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3b3544d-bcf8-53b8-8920-110d7916192d",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33871 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2119d4ee-bcbb-58fb-adb8-3d835e94e495",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcfddd0f-7382-5b4d-9a73-7a93097c199c",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42578 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6587578e-b9c2-54e2-8e16-f33f3de3dae8",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07f5e349-e336-5ca7-9662-1b083c60c949",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42580 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f10bd58-b554-5bae-b22e-0f2dec53f401",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42581 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a7362f-bf98-57c3-8557-885648c044e4",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42583 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5fd20a-3975-5ba0-bab2-de6ff3f59ea0",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0f02b84-2b52-52e4-8ea7-4741abdedc26",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73fbfd5-b102-5264-b0f7-c3c3e96857d1",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42586 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8233190f-839e-56f6-aa63-cdde2ba5e66d",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42587 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ad69c9-4da2-57a0-86ba-b3d040db43a9",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5726249a-5b5d-509f-b167-a8e5179210e1",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44249 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4732e771-4979-5b31-abac-b83271950898",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e228a67e-cd4b-57f8-80e7-8e9b3059883e",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4435c6d9-0b20-53dc-ab92-bc2d59380cdb",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a4f5cee-e008-59f4-8403-3954b2738bec",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af8d33c7-00df-5e07-8d91-e449e523958e",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ec9f542-5fe5-5b95-9df0-8d32cc2ac21a",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd50edd-05ae-5303-b732-54bbe012718c",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45673 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6429472-1490-5953-89b5-ffdfaee8b759",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370515ac-411c-5a5d-af1c-0caab65559ad",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50b97fd6-819e-5ae2-b94f-96eafa48f079",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47244 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0196e02f-92cc-5950-a50a-48a996baa593",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47691 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f86fc1-4f06-538d-bb3f-adcdd05fc7d3",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48006 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d869a40f-3b71-5040-b432-1c9ea46b3ab1",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48043 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40cb3eab-99ca-532a-a364-067d46946f59",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48059 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deb58d04-ed82-53d5-a559-b608a24cf6ae",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50010 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1501cee7-8a70-5909-a051-fa02d4ecbc6e",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50011 does not affect version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp. Patches already applied: bff98ee51b5d0b7ee25fd5005f2169f2a0467efa (already in target via d5b4e38845f5 'Backport CVE-2026-44890 to 4.1.130.Final')"
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11cc25a6-bf7e-5fb3-94a4-b37ed555d327",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50020 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d3eead4-b1cb-502f-8405-fbd2a101efda",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e935ac1-bc86-5035-9b95-32a2ecdaf071",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad380b3-6873-55ea-a32f-a7ff975e2b28",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52653ba1-8ac9-5792-add6-508813a886a7",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fe064a-931e-5cd8-bd07-04ab959380de",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c6d84cf-0bd7-5375-9525-6233e2844404",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c592bb9-8810-515c-97cc-022efc37c0b2",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce6f720-c814-5cd2-a22e-1ee8597d11ea",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56818 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:486a7465-be93-5643-a0ec-9de61f629db4",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc98442b-0514-5739-b710-c27814e3d440",
      "id": "CVE-2026-56820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56820 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7165d0-9175-5e4a-bc0f-152ef525783b",
      "id": "CVE-2026-56821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56821 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:208884e9-d9b4-51aa-9a11-e4ecd24ce5e1",
      "id": "CVE-2026-56822",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56822 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d65db24f-5a7d-5f52-8238-fdbf5d026f28",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7dc9025-3f54-57e1-a5f8-76a892f25f79",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5586ed6d-0dee-5c91-95b9-976dd40ce891",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f05d6d5-0213-54ac-95e1-44701a847340",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eae0f55-d892-561b-b5fa-b13668e6ad15",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04bc3ca5-ba6c-5dfb-9cf4-3de3790c42d9",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e13dc5-8983-5ee5-8688-e1dc7bda3bda",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5f9ad6-3d22-5389-8394-f1aadbe54b45",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b382b89-4bc5-5b9b-b1f9-10e4fca972a9",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b479bd5-121e-5eff-b915-0ddaac324887",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:144aa3f5-a4ea-54c2-9726-d732a774fc75",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b17188a4-8d06-5900-9504-e0ae8e0b2ab0",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f11b3c4-e45f-5c7a-af4a-78803466014c",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.130.Final-tuxcare.2 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.130.Final-tuxcare.2"
    }
  ]
}