{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a879faac-55b6-59cc-b43a-8cdb92ffa960",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5",
      "type": "library",
      "group": "io.netty",
      "name": "netty-common",
      "version": "4.1.63.Final-tuxcare.5",
      "purl": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a5d50200-2b3b-5382-825b-37ce17a6ff13",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6793e693-a30a-5e22-a4f0-999f4ef824c2",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70b2d67-a139-55bd-af96-dfac154a38ad",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56314925-005b-54f7-affa-e7d3ef245ead",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef3300f-e764-5622-8b98-65d3b44093f6",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:587bd3c6-6ade-57c7-b013-1f3cf0c4760d",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76096023-345f-5087-8e70-4e8520ba31a0",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49cae23f-01c4-560a-bd88-e2edcab46fb2",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba5c88e4-c6c4-5dc6-bbba-a16f6c8982ea",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-common 4.1.63.Final-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b37f41c9-0dbb-5c22-9365-125824a14d68",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efa359b-a3ea-522f-8f4e-bab164b4c620",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a4b5cd7-dd7c-5b67-8088-e2085503035c",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53acdddd-731b-5bc8-b77f-2133fbe9d6c1",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6e03ec-939b-56a8-ace3-78877b955474",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf7ca3d-6fff-5f6d-a2f8-10a170074f24",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315a2cbd-aa08-5736-8a0a-e99493b7a2d5",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25bf22d2-355f-5ae3-9f0e-6fd7bc69ccf7",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5717cfd9-bf94-5580-96b3-a6f0a3f97ea2",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e707faa-c8a5-5c53-9326-2b71d2f258d7",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4b9d24-569b-5e49-a54a-eb4e627f6844",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b67852-96b0-51c2-9132-ca6918c5352d",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a09db38d-a3be-55f8-8802-efb0fd00991c",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:251c53b5-1df9-5ba9-81e4-5aa92122a4ef",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2befb809-bf67-53c1-a36b-a6992c2454e6",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763b1f56-7aa8-5e8f-a417-c451f4f13c9f",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:704ee913-0509-51d6-8b1e-26890e7139c7",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f613c4c-7bf4-528c-997e-7d5a0f6cad7a",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b843d2ab-adef-5214-86d9-5b2f491804ae",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e609e38e-7cc3-5215-99d4-c566b4ac7470",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f359339b-dfd4-52a5-89af-eda34b265ae4",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eadac91-c21d-5eb4-9f65-c3d8714706fe",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baf66710-ca53-554a-9c10-46cfc50d2943",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b816760-7b6a-5246-808a-152df6dfd6ff",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b91273-150f-58bc-a251-a7d18528a117",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4b0b8b-c618-576e-a0fa-f7884a133216",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:040332c4-d73e-5de2-8127-ba0d79c6b001",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e4de43f-db41-5849-b859-708f1cade445",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44a2c21-eea7-5060-9ce2-1873efc4fb1e",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9fbd41a-3f62-5418-b4b7-1b630ebf84e5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e412512f-08b6-5ad0-8ff4-27120f983ea0",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46dd0e6c-5e82-572e-98a6-aecff325400e",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79478ab8-7932-592a-a819-ef76f81717df",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4221cf34-8fb5-50dd-bd37-25abbffefaf3",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec903aa5-84c7-5d29-9df4-b45e2fce843d",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd01069b-84c6-5786-acf1-70e8e5d72fec",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a78f2049-4728-5e9a-ad35-ec001d52fbaa",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48043 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d232f9-81c3-53f0-99a6-93ac85159d46",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dbb33f0-a043-5274-ab3a-aff9e6b7cc6b",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55046fa-805a-5aed-bb8b-bd549d466a5b",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d58858b-da86-5901-a43e-08478570bde1",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a445587c-8261-5c58-86f4-36dba1154850",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee2f8804-e4d3-5609-893f-d6f89782ee86",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:389ad82c-3400-588b-9c2c-46566a4dc77b",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa50ed01-d163-5611-99c3-bf5984eaab2e",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3de149f8-9d1b-51d6-a049-c91a68c4e1a2",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e017e332-a763-50e3-9bf7-9df752c953d8",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41dcfab-c051-5f11-b1ac-e7074225cba3",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.5 of io.netty:netty-common. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1a09b8c-bf3e-58dc-86fa-045344795610",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56818 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92dd7c3-8974-57a8-8b41-189eb1440130",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f30700a-83bf-5548-8ed6-f7b30c2f1f77",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:977b3d7d-992f-5bc7-b1b9-3e5e1daad3e0",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d756f2-b3c4-5cf6-9629-4574aaffea3f",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b054ecc-86fc-5ed5-8802-f3f48be13a7d",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68cf5464-9ff7-51cb-9b72-d6e3d67c6782",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac2643e9-9b1a-51e1-ac3a-c5fa7cb9a214",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6b2c2bb-987e-593f-8bf1-6bafc3f8359f",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e218bc9b-be6d-58f5-ab3c-4872ea60bc28",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d3a057a-2f8d-567e-8101-9da1b108e238",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:523d8882-319f-53b0-8cfd-cda8e48bec1a",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa7b083-52fc-538c-a126-d97a0762501c",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da40feb0-76c9-54f7-82da-01a2288b3a21",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581069db-e08b-5a05-9f4f-0dd6dda3668d",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0e8db6-d225-551d-90eb-0ad35493fd18",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.5 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-common@4.1.63.Final-tuxcare.5"
    }
  ]
}