{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a7cebf17-83e7-5fcd-b2cb-02d2c9bfdeea",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.73.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f506f12e-4878-5f6a-949d-ef5daa5402d9",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b7865d-e825-5f0d-9f58-387a2e7fac4a",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1be412e-fd22-5c59-88c7-d92e4a449cac",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f112842f-c676-599c-9e59-4d214e4a3f47",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b86a85d-2913-5532-bc5d-3266a4ea146f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173491cd-650d-521e-8797-b1a427733949",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.73.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0234cfe8-3d22-55e1-a045-b15b35bad9a6",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd8b0c95-5658-580b-a72b-6fc9da4aa7af",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde4fcd3-bad4-58e4-aa47-75b22fb32475",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6caf0178-6db3-5d27-8fd5-e22b552268ac",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0dfa6fd-0c4f-5041-9c30-99446dd697e5",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e108b07-5102-5902-aa98-ec026e4580f5",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd0789d-3af0-560d-a7fa-4f6ce56a8dc7",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cefa5d12-69cf-5fba-be6b-863bd4a7c535",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c595ddf8-d4ce-50a7-a708-727245c12f83",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:526f9b10-a18e-5174-a4c9-c391e03c03d1",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b272602-3068-50cf-b3e4-2cd34f81cde5",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1ada57-c766-565b-84c3-01e648112f95",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c884317-6d39-5549-a82f-6e9b212492f3",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0b9bb6-0266-5a5a-99fc-e1e7a777c1f9",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6bcdf42-c14b-5c90-8658-9d901da2a670",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6015357b-90d1-5fb7-9feb-d93995caee6f",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73a816fa-479f-5eff-9199-85775235f9c3",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c94b405f-e0d3-5445-b7c9-5a19b5f56762",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab50488-8cb6-576e-80a6-eaf6ca9a85da",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7992c07-b0d6-5440-8529-1a3c5f87c58c",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c20dfd-ca6c-529f-bf60-e5602e619cb9",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f9ce600-7645-569d-abb4-2f24f34467fa",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d7b039a-95c7-563a-9b3c-85a8ffce6462",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d38264-536f-5183-8b78-a47ac501f4de",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd1ab36-fbd2-53b4-bc71-e14179f4fbec",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad55326-12e0-5af0-9a69-01f8aa2c10ea",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ab26d3b-967f-5410-ae8f-abca0348913d",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1efbe64c-8ad3-5b12-9669-b5bf715fc261",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25a08ad5-5899-51d8-9121-63d1ab2547cf",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3b45cb0-3d4a-50e1-ae39-1eb161cac6cc",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2b3fa39-92b8-513e-97df-84773af5f6f9",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:492faf91-1e4b-5ef8-90d2-d1babdbc20b8",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96f4956d-8f5d-5a03-9de8-fbfb3e2a5edb",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e70f1cee-29df-5956-bc2a-6c6f73078d37",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65fe73a6-1734-522b-8d6b-c83cbcab2f9e",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b719ab9d-532d-5534-81d3-d4b2852f779b",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b7b0bf8-de77-5bb5-ac80-6052516e4441",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:470124f6-ac8b-5ccf-ac4f-3b05b7515b5b",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:212683ad-91ef-5b39-8ffe-d731bc7ef1ca",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2318e16f-12d2-510d-9651-5cb0ba999e9a",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11333d83-4fb4-5666-9d98-421444acd93c",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84e54437-2fc9-53dd-81e4-1f67307841dc",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38b6300-69b0-5f0e-8b08-b571e9035160",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57690a31-00fe-53e5-8ff2-caff5e43d2ea",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e7d12a-e7e1-5205-998e-bc65ea3539f6",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fecaa9a2-ff83-59ed-9723-def966aa45a3",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a702dd0-57d9-511d-9b46-cc23e7307c62",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a755b64a-c295-5562-a958-8813bb8d909a",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af215da0-b86e-50cd-8fa5-ed2f206a95f6",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13898601-6179-5fbe-a82d-43e889678309",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd5e7aab-3137-5a82-84e5-97f0dd196827",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1446fe3-32dd-54ef-bd66-baaec8ce056e",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7526b7f6-b15c-563c-ad0d-3195cec7e3c7",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e12348c-1c98-5506-a5da-c53400d1e63c",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac67a845-08e8-5dcf-8a33-6367efd38046",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c95f80f-6606-5887-909b-318cde9f3f13",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd4edbf3-c2e5-5f00-a823-cd88f330bf87",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97d6e125-2133-5e83-a507-5700db0960ef",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2711cb7-2302-528f-8d18-210cef066cf7",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da505104-13a7-5ae7-89a7-c13d072eae09",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e1d3fec-cea3-52be-afe1-26aaeb5f20d9",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a1f4466-07bd-5f5a-8063-77dd35ca3252",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7663ea9d-2bdd-515d-adb7-c0dbcf284e21",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84093185-6c77-58a9-a7aa-84bddaba6ef6",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.4"
    }
  ]
}