{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:db4ecf0c-6360-5763-af8a-87c3ab6a6ae6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:584a8bfe-36a4-5e93-a469-53c0990b4082",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdf4bb96-8090-51d5-a9fc-5ec23b44ef0f",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:876ebff7-1cc6-502a-9dc3-0d6be095e435",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcb6893-83b1-5c00-85ef-10a17f823fb7",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb615d25-e652-571c-ab5d-c307282b02ae",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56dae157-efe8-5c89-bea0-7d7a789bc9b7",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-haproxy 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b23003-588c-5fef-a39e-fd44db57e2be",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bb509b2-ae2f-5432-aaa1-021b53eaff68",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:097a0eaf-7631-5891-9b13-93e9217bae79",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa5307c2-7c58-5d1a-83f1-bb455f5ca659",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dba5427c-5f63-5999-9d10-084ecc0ed53f",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddf9f08-2149-53fd-8dcc-326edd3b69a0",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57114725-e389-5761-abf3-ae993c8e3918",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc64eda-bd2a-5ddf-829b-7ebde86e4e8e",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30ca5b08-4a24-5428-a6ec-126c1e10b2f9",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205d0dba-4b3e-5883-9ab9-fee60cf1c5bd",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085f80b5-4af8-56e7-b506-1e354074d9b9",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b53cec-bcb7-57d3-96bc-701616c74f71",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9961416-9494-577a-87e1-caa234352dc4",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5136e7-bebe-5768-a953-96eb37b229c2",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a54ad0c-92b2-50ea-ab53-f203ee1c5835",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1503ee-16b4-51ce-88ec-b0de756f0649",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5453f1d1-9edb-534f-9aac-5f3b5f7f42a4",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060861e7-538a-591a-924a-3b6ad0f5dfde",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e0fb2e-7a15-545b-802c-3b1a5ef82956",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcc1ef39-526c-5d99-bfd0-6098984c4e2a",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcedda11-dad4-5a3b-abfe-313bd2037392",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e50496ee-9f65-5105-90e5-3ce10e62f14c",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce84a40-f636-5017-a808-d77abad5f195",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696c3717-c87e-5648-9a31-d456450e0aa0",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b0f8ea7-cfb9-5e22-b89e-dcb0c8362d71",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de527adf-a945-52cb-a08d-0d755e536731",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287ec89e-458c-59ab-ba46-5403ebfee797",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1663b5e9-da84-5b72-b343-ba7f7a5c92f8",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:462f1ca0-e480-58ef-a693-41c09eefc247",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb2c575c-5dc0-502f-a76f-4dbbeb2fc0ea",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46795dff-d43b-5449-b9e9-f28eaf7502c1",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:225c84ce-1a42-5c76-b4fe-dd988d04296c",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3155672d-a133-58e4-b3cf-31a27de7118b",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79db1fe6-131b-5ef4-a2a7-162e816fce84",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6adf4a3e-66f2-53a6-931a-0d4bd2a0492f",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc6b5f5-97ee-5986-b6eb-de00db3ed621",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b438ed6-3c36-5c38-98fb-7baa6c26d3b9",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c66a1438-6392-55ae-b2cb-1d050601584e",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e58f56-f132-5751-ae6a-77524f40d521",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22f6d941-7da4-5446-9897-e92ba7269d50",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79ea58d1-325f-50ba-9399-b06ca4adc676",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395cbaa9-aeba-5666-9c62-b071e2d811b8",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe7d2c36-4e5d-55d4-bfa7-e1f37be1b353",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfa3ce3f-29b2-5468-8834-44537b16a029",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957fd028-9439-57a1-bccf-9eae8b0726c4",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7c597c-9e91-5c27-a6f0-0f186e90fda6",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7976560c-f2e2-52e7-af24-e92d7c4d5ab6",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:088c5db2-9d28-5c04-800c-4c647a824d87",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b535f9f-96f2-511c-9ddf-60f99447138a",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba1caaae-83b0-5c4b-9ac6-235839310900",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2100c550-47de-5d03-8e42-aabe19e5a6e0",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef63de5-3254-5f2a-af37-67e9d7748f92",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e17038a5-2073-5d2f-bf64-e0881f92f4de",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04628c41-89fc-5eed-94ae-c9661e84f303",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc3a9f4-fdd0-5a2d-a80c-4b632cd40f07",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb4df8c9-d2c2-598e-a51c-d4dc1e7f376c",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02df1b2a-f2b3-5dfa-a20c-6e12474c099c",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76a5ab9f-cb4e-5a4c-8dcf-36e53309b6ca",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f1ddc7-c171-55b6-b5f5-de10f5e9eed8",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6b147ef-9422-56f0-8b0e-4a58b0b332be",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.73.Final-tuxcare.3"
    }
  ]
}