{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cfa832cc-48c8-58ae-b1a4-b692ae07e791",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-http2",
      "version": "4.1.73.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:231c3686-92ad-5f33-acd3-998de15d8f9c",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bc88615-f16e-51a5-b2a6-a92e15a8e50b",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4307d553-5409-5be0-a2bf-9fc588a83a7d",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a58fc7-8455-52a8-8a05-0623c109f023",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5173260-be52-5d3c-bdc4-b38981c32cfe",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9160bbcc-d184-57b4-8c37-1a9b82965db4",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-http2 4.1.73.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ea0081-22ad-5a7b-b339-cff0724640b2",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce91681-dedd-5ec9-902d-ea9f32ffaff3",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a758a3-3d85-57b0-a3a4-4e5872c57fac",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d82e3d9-f95a-5f6a-a70b-533242707eca",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55a6f06-76c5-5628-b539-97b4c9babc8c",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46124506-1cad-5260-97ed-60eba9218bd4",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:277b54c3-2865-5f29-9cd7-ce898550d791",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:069ce98c-42bb-55a1-8fb2-e9da7347dd63",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f3699f-5679-5c3f-a072-54fa478d19b4",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69068677-9af2-5656-a8e0-b85cb1a2982c",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b3ffacb-83da-5727-a2d2-c39e238bc647",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b40c981-73de-5011-99f7-c5ff9674a020",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a2e3e6-1b46-5e59-9d0e-cc6456936d39",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cb20354-c983-5b20-8fc3-636022f0bf0d",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4469ae59-954d-5ed0-8a47-9df4f8b846c9",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14736c4b-f675-52dd-9f4b-cf9ae443161a",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a9d00db-309c-5069-aabf-73850980304f",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5584e049-1fae-55d6-bd7b-75a3057dfeb8",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e382f149-1169-5f30-8de2-8b5e6d1ba1ca",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca80869-d596-534a-a5c3-23f5bf164207",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3c62ba-eac5-58ba-aa5b-4acb5f379ef5",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dc659b2-d8af-5a9b-b0e5-d4358992d550",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b828810-c9b8-5401-8efa-6b457826d74c",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb605ef1-b574-54c0-8b0e-6216e9c2dce5",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88de7229-4f27-537c-ac25-1bb34ff6bd39",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45dbf855-8fc4-5f32-a7d8-467fe2538a82",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d95fdce-f2ba-5eff-9eff-39cc55284a45",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74c8701-e7ba-5350-9feb-4ea07b081e9f",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ac8ec5-e40e-531c-927a-2771e5312038",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b73b8f81-884e-5ed6-86b9-5a1ecb2d3994",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20bebcf2-8cfe-5a56-8369-54c813eee1ad",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6975802a-521e-5303-9a03-c82275977e10",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-45674 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7960bfe8-e463-53d9-8cb6-8e1dc087c14e",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815d93bb-110f-5f6f-add9-a69e0c2357da",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71d5bbdf-359d-5b45-825f-0c5c8437a92e",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41aba879-5652-56f3-a3f0-8d23160db942",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe7a07d5-b60a-5f40-bade-2a06a0af0352",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccaae907-0ebe-565d-9d54-e619123de6b7",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5690480-0147-5383-b03c-af91432ad9c3",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85fc669f-8a7b-56f9-aab1-4c5f65a3ee72",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a025006-4d94-5010-95b4-a9f44de1d8c5",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e90de2f9-a830-58e3-9d6b-e24a61dcce37",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae6c886-9e79-52dc-a799-302da8612850",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0dc5c4-8990-51a0-9ff7-ea018a2ea95b",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f761aaf7-1526-5659-a523-769880ad3511",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94e7eb0-61ca-5d75-9620-3f4e19624537",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc8a6fe-5d99-5491-b91c-2c4814cd9944",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c29bab07-8c1d-5b8f-b153-0f5cd4f6836e",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b4009ad-67ec-55ba-bd99-be180b7e78ba",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a93c85b-40d5-5c48-a7fa-2fec6e63f034",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa30189-70ae-5ed8-be62-654f83053211",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3661ef83-8dbc-5428-a14c-5f405612d17f",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5649727-4102-5897-9dbe-99bea054b35b",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:212a5a09-7ec6-5f77-8e14-a26725ad5579",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fd6dfa-495a-5686-93bc-802eaee3a072",
      "id": "CVE-2026-59902",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59902 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b6c9ca5-ad8d-5cea-a8be-4a251ef23d7d",
      "id": "CVE-2026-59903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59903 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fba1ea5e-994b-505a-906e-224c420c192f",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c801c56-2ad2-5cb3-bc74-17ee41aa4f21",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9e1cc1c-9879-5fd4-bae2-fd41b746ee4f",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8daf278e-84cf-5aee-859e-11af7374735e",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06c3d8e-5d69-5385-a42e-575c094f32f0",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c093f128-ade8-5da7-b882-41365c938049",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f42e007-10fb-52a3-ae60-5d6e45797dd7",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:412997c9-cdc7-56e3-a4b6-64c5592fe531",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.4 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.4"
    }
  ]
}