{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd2920d4-3744-50b9-a6d6-697b48387195",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.75.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d730ede3-c778-5aa3-bd57-9e083ce9738e",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3eb375-e873-500a-8c70-58a416d92ff7",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a9fead-8a67-50e1-94f9-9446b5111573",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b22c664-f8d1-554e-8fb3-445c0872b56a",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d494480-736f-5151-aca5-7dfa3f593d5d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f72aaa7-9fdd-53f6-aeda-5f8eafb5209a",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-haproxy 4.1.75.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1a331a3-9a54-5c78-80d8-ee074fd5fa98",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bc7e9d2-20a7-5eb4-98c5-af430effdd50",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:168d70c9-5561-5a28-af8a-f019a2c9379f",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d670676-36f0-599d-b34a-85232acb114a",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39864ccd-cc90-5f8b-a3e1-001bbe8cb37d",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29b80196-b55b-5906-8a09-07c633e36e18",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ac52e9b-ce2c-55ea-8a75-51982c959af0",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0883bca-d70c-5bae-9d2f-691c5686796e",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae6027b8-75d4-5b84-b7e9-ef55ea98f113",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5be5f83-0ace-52eb-b801-b81f2c8c0df1",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fbb1cfd-47c8-536e-83ab-7ae6e29e2c9a",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03c014c1-23e8-5152-a44c-40a69cede506",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9241ad4b-ee71-5403-9b59-c4b7e586f554",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df85cb04-cce3-50b5-87c3-18332b0f8acc",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:844de586-16c8-51de-a2bd-2237a8ba608c",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5acbb9-8b73-59f8-ab09-356fd93f2787",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5339428d-4f00-58ed-83c6-f7b115d9a62d",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b394e801-d2b9-5ba1-bbcd-668a701989a8",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4aa6e2-f455-549b-9071-8e34cce7f64c",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a2e40a0-5e8b-5c39-a9b5-97c153bdc798",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1935490a-3dae-5e1d-8bec-c3c65c19d83c",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd36e7c-67b0-569e-b396-9ba01b942f0d",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a43a4d-ecf7-5c34-bac6-480cad66cab5",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66fc9039-ad10-5d37-b026-817e9f7b4821",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ed414de-cfeb-515b-9a94-e6f90001eb53",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d3a7887-43e3-5c8a-b4eb-8b1c2b83bdc4",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e957e02f-bc4a-533a-9057-244952eea398",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e970dce-ad6d-5cec-9e0e-a469cc7926f9",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a69e15-6b72-5a8c-9b81-40028416cb48",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21f32e75-a174-5bef-90fb-07b39e3b1ae5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbd139fc-5560-55e1-9a13-38e4c2eec96f",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2658507d-a87a-5509-842c-81932868f0d8",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737c429d-1384-5f63-b48f-e3498dc673cc",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18fd3f7b-b1dc-5595-b81f-fc7769d0f731",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57bbb0d6-223d-5997-8f87-a757a2b6e150",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81800b0-c349-5f73-98ff-01bf258b3aad",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e029dffb-b5fd-5937-8f4c-72e1bc08574c",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4775443-3b92-5b5e-b953-f26b3ef8957a",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993012b3-ccf8-564c-b482-28d9b5645ad7",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a522fcf6-d4ab-583e-9226-db5d4d0dd54a",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a754e0d-f055-5a5a-a8c2-5b97d8839778",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb65b82-d95c-5b1d-b7ba-681d965fb871",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15329959-96db-5908-b37e-aae8cebc229c",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930f78cc-f798-58de-855d-1ea398fd7c22",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1fd9a6-be75-5589-a558-dfea616e3570",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea19951-775a-5916-9ccb-ef294259c71b",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c28b5d0-8aab-50c2-9836-066fcb87c3c2",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996305ca-f42c-541d-9bfa-6653bc612bf5",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0fa49bd-8142-5074-907d-141de4345353",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy. not_affected \u2014 The target version 4.1.75.Final (released March 2022) predates the introduction of the vulnerable feature by over 4 years. CVE-2026-56818 describes incomplete cleanup when the `maxElements` limit is exceeded in RedisArrayAggregator. However, the `maxElements` configuration parameter and associated exception handling were introduced in June 2026 (commits e51c64c964 and 728c98b8ec), neither of wh..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec3ecd3-90a7-5f87-ae3b-641eb3953a99",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba159d7-5335-5f4d-82ec-7d59d54e8e95",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d644bba7-4739-59b8-abc2-fb284768a7e7",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c133d32d-1c62-5fea-bd41-0e6e3848813f",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba32aa7-0d63-51af-b61b-cd4531288407",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:917f0404-dd99-50e3-9b64-bb1cfd8ddf0d",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e168dfeb-a21b-5a32-9cee-2769b860a345",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e765aa-e86c-5124-8274-2bb287b4b5be",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b078d552-c24f-54df-ad0c-5f37b0cea5e5",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a437b42b-7c91-51ab-b81a-fd5d56e3e54b",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566ac09e-b7b2-5924-90dd-f795fd6a295f",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.75.Final-tuxcare.4"
    }
  ]
}