{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:463a88dd-ed70-5b5c-a420-a4fed4d9fb7d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.73.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9218fe3f-a96d-59a7-813c-a6a0533714a7",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f819b6-1eaa-5b64-8096-5a7ef54444fc",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5345ec09-adfc-52fe-ba82-11d096298b5f",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:855e40ea-2049-582f-a4d9-ddf1a4641f1c",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34cdcd07-78cf-5b45-93c7-fc2d1896222b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13de01ba-c88f-5d15-a95c-8f0bdc37ce92",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.73.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4718eae-a448-532c-b67e-549cf633157d",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae3f730-b832-5e65-a22f-5998c3523729",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab58b11a-9caf-5213-b563-d1d14d95eb72",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05220012-c12a-589c-bfbe-da38ebd6a000",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56349121-753d-584b-865a-2022c3583617",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1cb644-fd35-5707-81ab-e95e7adcec8f",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c9cfbb-0794-5798-ba13-235bd2ba4b1c",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f89c72e-1ac3-58eb-be21-f46fb569f43d",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27353f9-5571-56f6-bad1-9d109daf732e",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f803f24d-8fc8-5c1b-b732-ac5b3841ea6f",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:688958d3-10e4-5ce0-be54-8cb38d72c925",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc9dbe6-9fc3-5c30-ac74-2624910e6b38",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c1e440-e08e-5a6f-ba59-2d02eeffafab",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f354fd-fc41-52d2-9598-bf4aab890932",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d800d831-57a6-5071-b3b5-efd30674d659",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2930bcf-c03c-5368-9bef-eb67ad88aec4",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee839d0f-2f77-5eb5-bcfc-6600be70e742",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74ee818-edc3-50cc-9aa7-b80c90cc186b",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b8a2437-4e93-53b5-bd7a-ec23c519a1e4",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887897b3-ba8c-5f15-82c6-ddf300a05142",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee111c3e-2e0e-5660-aebe-237ec308b907",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f16a3603-6277-5bbf-848a-d18f5749e2c7",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a152b77-6dae-5123-bb3b-4df836db42dc",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:283e7edb-aa7e-55f6-a504-0dc3cff08223",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200a5339-58e5-5001-8d2b-09d368ef879e",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d16e4cde-2f76-5b6b-a675-7a882b09df3d",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2e88301-dfcc-577d-a009-ff0a7ed56d83",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba560ea1-a5e6-558e-9598-5e0ea4db74f1",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70dd8d15-4e67-5279-a105-29d74d0100ad",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62911543-7bb4-5f6c-a26c-6c0bc5b5b84a",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a9fb59-2459-5c39-9f19-94b4bdd6805b",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4933f82f-6ef5-5ab9-a9d6-41701c50270d",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb4e4dfe-4d56-5c98-a966-e265c1e5b1fd",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf6a950-5061-5371-9a53-a5ba29416397",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b082d19-6942-58d0-bc5d-90ac42e94581",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3dd463-da77-53f1-b28e-a74529d94a7b",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4ca250c-aece-59c6-ada0-348eed93e42d",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68a2eaf7-6390-5ba3-a564-6e943f0cdc9e",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30206119-217d-58ed-96fb-eedfa0fc533e",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ec41f2-5125-5d8a-a6ca-a6af1fbb50e9",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c4434fa-acd6-591a-8017-795f82bbef79",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f59cf2d6-43e5-5446-a467-66c582499f7e",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f88b86b-de3c-5589-bd77-c18fda7ccc08",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9c6c440-d96b-509e-8d71-0e3b97583914",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b21a2c-2bf8-52f4-b119-17df6ee53107",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14071b9c-ddb6-583b-8ced-72b0f0462f37",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f2bbb4f-199a-52be-a56d-48759c48c80a",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf72ade-5190-5c4a-82b4-3d7a6b33bc66",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63454d69-496e-5694-8c18-557f55f82208",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5d9cc0-212e-54f0-9c8b-2f8b6effb26a",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb848a38-c59f-56b1-aaed-2869ec5d6fa4",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0462eee8-3955-5de1-ac9d-b92628f80b52",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e26e1354-e4bc-56ec-b1c0-9f7b2967e51f",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9d6620-1193-51f0-87ab-5ef107c00d3c",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08e0b543-071f-5d0f-953a-7ab16f827976",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2e6cedf-b5df-5f63-8d5f-33c2ea472fca",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b8f383-b2bd-5c8f-8119-80230dfd55ff",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f77a8c88-a244-527b-a3c6-821e602854b2",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5291388a-1e6d-5acd-b833-416435e5f8bc",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70aeb2ad-9f5b-51f0-914a-a52daff77bb9",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89188f83-2811-50b5-a1d0-310f3cb0c8df",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cab26e4-0051-5dda-80c0-b973f4a592ad",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b0f50d-ee67-58ff-895e-8678dd6e3236",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb00e13-4eed-5e00-bf73-7d22ef0a9f87",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.4"
    }
  ]
}