{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f16fa8cb-7ebf-5c91-9b81-3cfc3651e227",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cc6eed41-f106-5fe2-a5f7-0a0886dfb5b4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e23cfb84-f939-531d-8184-58e9c3dc910d",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1521c5d-52c1-593b-9aba-8305d5980668",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bcab2ff-972c-5206-bfa8-ed7a0a422e25",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daee76b4-59fc-5a61-9b27-fe7a4350daac",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27504f2-8947-5650-8e16-21620a90db80",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5536b6d-4ede-58a6-863d-84ce1ad333d8",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f699cc54-855f-5346-b286-4cc21cb6944f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65a7b0af-57d3-5b6f-bfd5-05aec115d6ef",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c2a31f-a534-5690-a985-17e9964887ba",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea7bb529-c137-5bcf-b430-5dee1f892a32",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f535b81-2321-5a39-84e7-9740b63fc33d",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd2f951e-afff-5ac4-8e76-43319adc1fa1",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cb392a3-b0b0-527d-8870-155c096d99d4",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7633c12-bbf3-5e9b-a3ef-d57854eb0d60",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51a1679c-6b97-5d0c-b465-76b89ad2d46a",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e067e9af-c7b4-5d27-9929-c8918b1f93b8",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83501430-f5e6-52d2-a39a-0f4d84c24d89",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc89bffc-8bb7-5d47-84e0-c7f14242453a",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84714535-4694-51b5-9bba-bafd6840ccfe",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1c87da3-b641-50cf-9cd6-66eb465e8bc1",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12611943-8421-5a41-8886-e177ab5a3de7",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20432e2-b82a-5228-8b10-9284fe54c130",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184b4255-a90f-5a39-8284-6d10130db133",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01736945-b69f-58a9-81c0-3e0f4ffaef64",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb52dc0c-b44f-5b0c-b37c-f7c07c598c6a",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d70ff6-6f84-521e-8767-6fd07e461957",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b63e432a-4c72-5d62-8b33-5fb77622e9c9",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692828a7-91bd-5a43-bc80-e3f8900a5f69",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4116578e-b209-5170-9dc1-58f5cba530b4",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e966915-4561-5497-99b0-6cf91605fde6",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b8b86e4-e8af-5a9b-b339-19dceaf8132e",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c90c6b5-ac36-59c2-bb30-2d6f48b45a7c",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908d5d96-b4c7-5dd3-ad35-033100f59e6b",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20bd23ab-1bf4-5b34-8354-015d9de37eba",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e021e8-f0c4-55b1-85a7-72df6e524148",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7117f2ed-4a47-5b0a-aa87-cd0a2c0366ba",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30012d3a-9d0a-5a61-8b94-9eb8d733632b",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896f45a0-ca86-5839-8685-8adf13442dd3",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25de57e0-425d-5565-bc20-ad58c094c25b",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1af2ef6-88f8-5745-8722-b96022f484ed",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11fb1558-df77-5807-ba0c-bde0c70f3ed2",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6e6e78-cc69-555b-8c76-22e954d046fc",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6c8bca-1b20-5f26-b2a0-daaca4868b30",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13b15dff-1977-5eea-859f-8058601a70d6",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaec82f0-1a72-5616-871e-d9d76df38786",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:952267d3-e12a-5e25-8fd4-c2380521307a",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b723f436-120e-59e8-a488-08705e520076",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e1d897-f12f-5f08-903f-2da4032b20ba",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65d0bef7-023d-5f14-b1e3-706e58f3002a",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e4c6a05-db68-5ce1-beb4-7165a8e3b3ca",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f68aeb9-b8d4-592c-92d6-2114b677f972",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df0f5e1-eb57-5621-a141-57afaabad376",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c0aab3-bab5-59bc-8fdc-88a6dd44873b",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a1e7a7-1f1c-5dbe-8b6b-f99e1dac83f3",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fed36f1-ad77-56db-b94e-f598dcd2571a",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5ad663-b5c2-550f-ab24-101a49d68c53",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fc14dd7-cef4-5980-a282-f52d4a6c274d",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a57a5d-f82b-55ce-ac46-8cb41b5f48c3",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d88501c-a333-555d-908e-ac1e5a6a68c8",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243790f9-dbc9-512f-84be-0f28bfe0b9bd",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c342c0b7-d99b-5437-9f38-c7c50ff279f8",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da84dd43-fe55-59b7-b376-9fb4eb69ca9d",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77b6c3b6-4b08-5218-8b97-40de9903c66a",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68d0c9ef-79b3-5505-98ed-fce535ab226a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d16bbe9-cbf6-5caf-b8db-cf9ae8c1c0a2",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.73.Final-tuxcare.3"
    }
  ]
}